Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

84 results about "Initialization vector" patented technology

In cryptography, an initialization vector (IV) or starting variable (SV) is a fixed-size input to a cryptographic primitive that is typically required to be random or pseudorandom. Randomization is crucial for encryption schemes to achieve semantic security, a property whereby repeated usage of the scheme under the same key does not allow an attacker to infer relationships between segments of the encrypted message. For block ciphers, the use of an IV is described by the modes of operation. Randomization is also required for other primitives, such as universal hash functions and message authentication codes based thereon.

Industrial control system security auditing method and system

The invention relates to the technical field of security auditing, in particular to a security auditing method and system for an industrial control system, and the method comprises the following steps: aiming at a key control task, a communication task and a security task of a real-time operating system, collecting a period, a starting timestamp, a finishing timestamp, a central processing unit occupied time slice and peak memory usage amount data. According to the method, the period, timestamp, central processing unit occupation and memory usage data of a key task of a real-time operating system are collected, a task execution time boundary and a resource consumption envelope are set, and then an expected relation rule set of a task time sequence and resource consumption is constructed by applying historical data statistics and logic rule deduction; and meanwhile, the key length of symmetric and asymmetric encryption, initialization vector generation, hash algorithm selection, key derivation parameters and encryption operation context are stipulated, so that a comprehensive and specific ICS behavior specification baseline is established.
Owner:CHONGQING HUATAI ACCOUNTING FIRM (GENERAL PARTNERSHIP)

Intelligent variable frequency dimming method and system

The invention discloses an intelligent variable-frequency dimming method and system, and relates to the technical field of computer platform load balancing, and the method comprises the steps: establishing communication between a module and a gateway, loading a frequency mapping table, a duty ratio segmentation point, a safety threshold and a forbidden frequency point table, and generating an initialization vector in combination with parameters of a driver and a lamp; collecting current, voltage and optical brightness data at typical brightness points to form a matrix, calculating a risk value and marking a critical point, generating three-section type frequency mapping by combining segmentation points, and performing interpolation correction; and receiving a brightness instruction according to the mapping table to generate a PWM signal, performing slope limiting, edge shaping and micro-jitter frequency processing and outputting, and performing closed-loop frequency correction under real-time sampling. According to the method, by collecting multi-source data and introducing a stroboscopic risk model, critical point identification and three-section type frequency mapping are realized, and frequency continuity and stability are ensured by combining interpolation and forbidden frequency point constraint; on the basis, a PWM signal is generated and optimized, so that self-adaptive dimming is realized in a full-brightness interval.
Owner:SHANDONG BITTEL INTELLIGENT TECH CO LTD

Cryptographic authentication signatures for verification of streaming data

Systems and techniques are described for signing and verifying a data stream with an encryption signature. An example method includes determining, for a data block group, an initialization vector. The example method also includes generating, based at least in part on the data block group, encrypted hash data. The example method also includes determining an encryption signature based at least in part on the encrypted hash data, a private key, and the initialization vector. The example method also includes inserting the encryption signature into the data block group. The example method also includes causing transmission, by a network interface to a media server, of the data block group and the encryption signature. Finally, the example method includes causing verification, via the media server using a public key and synchronized data, that the data block group was generated by the computing device.
Owner:AMAZON TECH INC

A method and device for implementing high-speed operation of an algorithm based on a multi-level field cache

The application discloses a method and device for realizing high-speed operation of an algorithm based on a multi-level field cache, which comprises the following steps: a configuration management CPU sends algorithm parameters to an FPGA chip and saves the algorithm parameters in a RAM; a service processing CPU creates a handle and sends the handle to the configuration management CPU; the configuration management CPU generates a key number according to the handle; the configuration management CPU sends a key library to the FPGA chip; the service processing CPU sends a to-be-operated message to the FPGA chip; an algorithm scheduling module performs fragmentation judgment, and performs subsequent processing according to a sequence judgment result; a password operation module takes the received key, an initialization vector or an intermediate chain variable and the to-be-operated message as input, performs password operation, and outputs a calculation result and an operated intermediate chain variable; whether the to-be-operated message is the last data fragment is judged according to a tail fragment identifier, and subsequent processing is performed according to a tail fragment judgment result. The application can reduce the communication interface and CPU access times, realize high-speed operation of a password algorithm, and improve the overall performance of a password service system.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Encryption method and device for dynamic data of unmanned aerial vehicle, and medium

The invention provides an encryption method and device for dynamic data of an unmanned aerial vehicle and a medium, and relates to the technical field of data encryption, and the method comprises the steps: dividing an airspace into a plurality of initial airspace grids according to a preset longitude interval and a preset latitude interval, and determining a target airspace grid corresponding to the dynamic data of the unmanned aerial vehicle; based on an AES-CBC encryption mode, using an AES key corresponding to the target airspace grid and the initialization vector to encrypt the dynamic data of the unmanned aerial vehicle; based on a preset access control strategy tree corresponding to the target airspace grid, encrypting the AES key and the initialization vector corresponding to the target airspace grid by using a CP-ABE encryption algorithm; the encryption result of the dynamic data of the unmanned aerial vehicle is obtained; according to the method, each initial airspace grid is used as an independent encryption and authorization unit, and fine-grained access control is realized through a hybrid encryption architecture, so that unauthorized access can be effectively prevented, and calculation, storage and transmission overhead caused by traditional multi-copy encryption is avoided.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

Video encryption transmission method, video decryption output method and device

The invention provides a video encryption transmission method and device and a video decryption output method and device. The video encryption transmission method comprises the following steps: constructing a security parameter set according to an encrypted video encryption key and an initialization vector of an image group; performing XOR operation on the first L-1 bytes of the original data byte stream by adopting the stream key to obtain encrypted byte stream data; setting a network abstraction layer header for each network abstraction layer unit after the image group is processed, wherein the network abstraction layer header at least comprises original coding standard information and encryption state information; performing hash signature processing on the encrypted byte stream data of the image group to generate signature data, and packaging the signature data into an authentication network abstraction layer unit; packaging the security parameter set, the network abstraction layer unit provided with the network abstraction layer head, the authentication network abstraction layer unit and the original parameter set of the image group according to the transmission sequence of the original code stream of the image group to obtain an encrypted video code stream; and sending the encrypted video code stream to a receiver.
Owner:BEIJING ZHONGYU WANTONG TECH CO LTD

Distributed data content protection

Systems and methods are described for encrypting and decrypting data in a distributed storage environment. Such systems and methods for encryption may divide a data payload into slices, the slices including a first slice and a subsequent slice, employ a content encryption key and an initialization vector, encrypt the first slice using the content encryption key and the initialization vector, generate a subsequent initialization vector for the subsequent slice based upon the initialization vector and the unencrypted content of the first slice, and encrypt the subsequent slice using the subsequent initialization vector and the content encryption key. The systems and methods may then generate a list of the encrypted slices into which the data payload has been generated, and publish to a secure storage location, the slice list, the content encryption key and the initialization vector for the first slice in the slice list, with the slices outputted to the distributed storage environment. Systems and methods for decryption may receive, from a secure storage location, a slice list, a content encryption key, and an initialization vector, determine the encrypted slices to be received from the distributed storage environment. The systems and methods may receive, from the distributed storage environment, at least encrypted first slice and the encrypted subsequent slice, and decrypt the first slice using the content encryption key and the initialization vector, to generate a decrypted first slice, and generate a subsequent initialization vector for the subsequent slice based upon the initialization vector and the decrypted first slice, decrypt the subsequent slice using the subsequent initialization vector and the content encryption key, and combine the first slice and the subsequent slice into a data payload.
Owner:ADEIA GUIDES INC

Secure communication protocol for communication devices

A method for transmitting secured Ethernet frames on a communication line, the method including the following in a transmitter module: receiving an Ethernet frame comprising payload data from a network layer; retrieving a secure policy, defining the type of security to be applied to the Ethernet frame; producing an initialization vector based on an encryption counter and a physical address of the transmitter module; creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector; adding the secure policy, the initialization vector and the authentication tag to the payload data to create a secured Ethernet frame; and sending the secured Ethernet frame to a data link layer for transmission on the communication line.
Owner:SCHNEIDER ELECTRIC IND SAS

Unique initialization vectors for secure communication over multipath networks

Techniques described herein can allocate respective unique secure channel identifiers (SCIs) to respective uplink encryptor interfaces which provide intersite connectivity over multipathing internet protocol (IP) networks between a first data center site and a second data center site. A respective uplink encryptor interface can then use the unique SCI allocated thereto, along with a packet number counter value to encrypt and generate an integrity check value for at least a portion of a packet. The encryption can comprise using the SCI and the packet number counter value to generate a unique packet initialization vector for the packet, which is then used to encrypt and integrity protect the packet. The respective uplink encryptor interface can send the encrypted packet via a tunnel to a second data center site via a secure communication channel spanning across multiple encryptors and multiple decryptors. The encrypted packet can be decrypted at the second data center site and forwarded along to its destination within the second data center site.
Owner:CISCO TECHNOLOGY INC

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Colorful QR code generation method and system based on AES-RSA dual encryption

The invention discloses a color QR code generation method and system based on AES-RSA dual encryption, and relates to the technical field of data encryption, and the method comprises the steps: carrying out the byte filling and segmentation of a preprocessing data package; performing AES encryption operation on each data block based on the AES key and the initialization vector to obtain a complete AES ciphertext; filling the AES key packet by adopting an OAEP filling method; encrypting the key packet filled with the OAEP by adopting an RSA public key to generate an identifier; obtaining a hybrid ciphertext packet based on the complete AES ciphertext, the key packet and the identifier; the mixed ciphertext packet is divided into three equal parts, check codes are added, three sections of mixed ciphertext data with the check codes are obtained, priority coding is carried out, and a QR code dot matrix is generated; and obtaining a final color QR code based on the color mapping function and the QR code dot matrix. According to the invention, the security of data transmission is improved, and the information capacity of data transmission is increased.
Owner:GUILIN UNIVERSITY OF TECHNOLOGY

Data table lookup method and device, equipment, storage medium and computer program product

The invention discloses a data table lookup method and device, equipment, a storage medium and a computer program product, and relates to the technical field of data lookup, the method comprises the following steps: when a data table query statement is received, converting the data table query statement into a semantic vector; performing similarity matching on the semantic vector and a table vector set and a non-table vector set in a to-be-queried database to obtain a first similarity set and a second similarity set; the initialization vector is normalized based on the first similarity set and the second similarity set, a normalized vector is obtained, and the initialization vector is constructed based on the knowledge graph of the database to be queried; and calculating a correlation score, corresponding to the data table query statement, of each component in the normalized vector, and searching a target data table from the to-be-queried database based on the correlation score. Based on the method, deep mining and relational network construction are performed on the to-be-queried database, so that the target data table can be accurately searched from the database.
Owner:CHINA MERCHANTS BANK

Transmitting and receiving method, communicating device, and local area network

The present disclosure relates to a method for transmitting data by a communicating device on a communication channel, wherein the transmitting method comprises, for each temporal cycle:determining, by the communicating device, a secured data frame based on the data to be transmitted,transmitting, by the communicating device, the secured data frame on the communication channel,wherein each secured data frame includes secured content determined by using an initialization vector, wherein the initialization vector has a lifetime associated thereto, the lifetime being greater than or equal to a plurality of cycle periods, wherein the initialization vector is not modified when the data to be transmitted is identical to the data transmitted in the previous temporal cycle provided the lifetime of the initialization vector has not expired.
Owner:MITSUBISHI ELECTRIC CORP

Symmetrical encryption security reinforcement method, device, equipment, medium and program product

The invention discloses a symmetric encryption security reinforcement method, device and equipment, a medium and a program product, and the method comprises the steps: carrying out the first-round encryption processing of original data read from a second node through employing an initialization vector and a first secret key sent by the second node, and obtaining first encrypted data; segmenting the first encrypted data and the first secret key to obtain a plurality of data blocks and a plurality of second secret keys; the plurality of data blocks and the plurality of second secret keys are distributed to a plurality of third nodes, so that the third nodes encrypt the data blocks based on third secret keys generated by the second secret keys to generate second encrypted data; and finally, combining the second encrypted data sent by the plurality of third nodes to obtain third encrypted data, thereby realizing distributed multi-round asynchronous encryption of the original data, including the first-round encryption of the first node in the chain and the distributed multi-round encryption of the third node in the chain, thereby effectively improving the security, reliability and privacy of symmetric encryption.
Owner:CHINA MOBILE INTERNET CO LTD +1

A data privacy protection encryption retrieval method and system and a storage medium

This invention provides an encrypted retrieval method, system, and storage medium for data privacy protection. The retrieval method includes: dividing document set keywords into low-frequency and high-frequency subsets according to a frequency threshold; generating deterministic tokens for keywords using a key-based pseudo-random function and storing the correspondence between tokens and keyword types; for low-frequency keywords, constructing a static primary index using a minimum perfect hash structure, mapping tokens to hash buckets, and storing pointers to a list of encrypted document identifiers; for high-frequency keywords, constructing a dynamically updated secondary index using encrypted key-value storage, storing the mapping between tokens and encrypted document identifiers; during retrieval, the user generates a deterministic token for the keyword to be searched and uploads it as a trapdoor; the server queries the primary and secondary indexes according to the type; and the document identifiers generate a key stream using a derived symmetric key and an initialization vector, and are then XORed bitwise.
Owner:BEIJING DEXUN AVIATION SERVICE CO LTD

Distributed storage data protection method for cryptographic algorithm dynamic reconstruction

The invention discloses a distributed storage data protection method for cryptographic algorithm dynamic reconstruction, which relates to the technical field of data encryption, and comprises the following steps of: determining an algorithm capability set and an alternating window before data writing, calculating path hash and generating an algorithm reconstruction vector, deriving a session key from a root key and signing and issuing a key algorithm capsule, forming write context data; the method comprises the following steps of: performing deterministic fragmentation on data by using a write-in context, generating an abstract from the tail part of a fragment, performing hash synthesis on the abstract and a path to obtain an initialization vector, encrypting a head part by using a path-sensitive authentication encryption algorithm, protecting the rest part by using a pseudo-random mask, and generating a fragment ciphertext list and an original index table; according to the method, after deterministic fragmentation, an initialization vector is synthesized through a tail abstract and path hash, path-sensitive authentication encryption and body segment pseudo-random mask are executed, and fragmentation-level anti-replay and high-throughput data encryption is achieved.
Owner:SUZHOU GUANWEN STORAGE TECH CO LTD

Recommendation method for refracturing target well based on TRA-SR architecture

The invention relates to the technical field of reservoir yield increase and transformation, in particular to a TRA-SR architecture-based refracturing target well recommendation method, which comprises the following steps of: collecting production data of a to-be-fractured low-efficiency well, a corresponding expert score and data of a refractured well with a good production condition as a target well construction data set; through a Transform embedding layer, each well is converted into a dense initialization vector, and position information is added to identify a sequence relation; the expert score is integrated into a multi-head self-attention mechanism of a Transform encoder part, and global preference is calculated; calculating the similarity between the to-be-fractured inefficient well and the re-fractured well as local preference; the global preference and the local preference are integrated into mixed preference through a linear layer; and after the mixing preference is obtained, a comprehensive score of the to-be-fractured low-efficiency well is calculated to recommend a well suitable for repeated fracturing. According to the method, the target well suitable for refracturing can be effectively evaluated and screened, and the method is beneficial to promoting treatment of low-efficiency wells, restoring the productivity and improving the recovery efficiency.
Owner:CHINA NAT PETROLEUM CORP +1

Quantum block cipher resisting coprocessor for computer monitoring system and operation method

The invention discloses an anti-quantum block cipher coprocessor operation method for a computer monitoring system, and the method comprises the following steps: S1, loading data to generate a random number and a secret key, and splicing the random number and the secret key with a preset initialization vector to generate an input state; s2, receiving the associated parameters and the plaintext, and performing preprocessing to generate grouping mask shares; s3, performing parallel encryption on the grouped mask shares based on an input state to generate a plurality of mask ciphertexts and mask authentication tags; and S4, performing linear reconstruction on the mask ciphertext to finally run to obtain a complete ciphertext, decomposing plaintext data into a plurality of mask shares for parallel processing, effectively diluting data structure features, and fundamentally cutting off a way of acquiring key information by an attacker through power consumption analysis. Compared with the prior art, the parallel computing advantage of reconfigurable hardware is fully utilized, efficient execution of cryptographic operation is achieved, the whole data processing process is completed in the register, and the influence of memory access delay on system performance is remarkably reduced.
Owner:HANGZHOU HUADIAN BANSHAN POWER GENERATION

Hardware Trojan key node and path feature quantitative analysis method

The invention discloses a quantitative analysis method and device for hardware Trojan key node and path characteristics, a medium and equipment. The quantitative analysis method comprises the following steps: performing quantitative analysis on 0, 1 distribution probability characteristics of each LUT initialization vector based on information entropy; driving a suspicious Trojan horse module by automatically generating a script to obtain a behavior list file, and analyzing the behavior list file to count the number of times of overturning of the signal in the simulation process to obtain a low-overturning signal and a corresponding security attribute; constructing a directed graph; smoothing the distribution of the signal overturning times in an interpolation mode, converting node overturning times data after smoothing into a dictionary structure, and constructing a three-dimensional continuous distribution network of the signal overturning times in combination with a directed graph; according to the method, static structure characteristics and dynamic behavior analysis can be fused, node overturning characteristics are quantized through information entropy, and suspicious Trojan units are accurately positioned.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

An encryption method, device and medium for dynamic data of a UAV

The application provides an encryption method, device and medium for unmanned aerial vehicle dynamic data, and relates to the technical field of data encryption. The method divides airspace into a plurality of initial airspace grids according to a preset longitude interval and a preset latitude interval, and determines a target airspace grid corresponding to the unmanned aerial vehicle dynamic data. Based on an AES-CBC encryption mode, the unmanned aerial vehicle dynamic data is encrypted using an AES key and an initialization vector corresponding to the target airspace grid. Based on a preset access control strategy tree corresponding to the target airspace grid, the AES key and the initialization vector corresponding to the target airspace grid are encrypted using a CP-ABE encryption algorithm. Thus, an encryption result of the unmanned aerial vehicle dynamic data is obtained. Each initial airspace grid is taken as an independent encryption and authorization unit, and fine-grained access control is realized through a hybrid encryption architecture, which can effectively prevent unauthorized access and avoid the calculation, storage and transmission overhead caused by traditional multi-copy encryption.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

Intelligent variable frequency dimming method and system

The application discloses an intelligent frequency conversion dimming method and system, relates to the technical field of computer platform load balancing, and comprises the following steps: communication is established between a module and a gateway, a frequency mapping table, a duty cycle segmentation point, a safety threshold and a disabled frequency point table are loaded, and an initialization vector is generated in combination with driver and lamp parameters; current, voltage and optical brightness data are collected at typical brightness points to form a matrix, a risk value is calculated and a critical point is marked, a three-segment frequency mapping is generated in combination with the segmentation point and is corrected through interpolation; a PWM signal is generated according to the mapping table and a brightness instruction, the PWM signal is output after being subjected to slope limiting, edge shaping and micro-jitter frequency processing, and the frequency is corrected in a closed loop under real-time sampling. According to the method, multi-source data are collected, a stroboscopic risk model is introduced, critical point identification and three-segment frequency mapping are realized, interpolation and disabled frequency point constraints are combined to ensure frequency continuity and stability, and a PWM signal is generated and optimized, so that adaptive dimming is realized in a full brightness range.
Owner:SHANDONG BITTEL INTELLIGENT TECH CO LTD

A method for processing financial data with improved security

This invention discloses a method for improving the confidentiality of financial data processing. In the field of information security technology, the method automatically identifies the source department and data type based on the submitter information of the financial data, determines the confidentiality level of the data using a confidentiality level rating table, and dynamically parses the key length and arrangement rules accordingly. It uses the characterization conversion results of the submitter's account and submission time, along with a random string, to perform multi-source fusion to construct a high-entropy basic key. After being hosted by a hardware security module, this key is intercepted to form the final encryption key, ensuring its unpredictability and security. An encryption algorithm combined with a random initialization vector is used to encrypt the original data text, ensuring the confidentiality and integrity of the data. The encrypted data is segmented according to the key length, generating a random number sequence and binding it to the data block. The number mapping relationship is stored on the blockchain. After being encapsulated with a unique identifier, the data block is randomly shuffled and further divided, and finally distributed and stored in the cloud.
Owner:JINAN JUSHI INFORMATION TECH CO LTD

A large model inference deployment method, system, device, storage medium and product

This invention discloses a method, system, device, storage medium, and product for deploying large-scale model inference. The method involves dividing the vocabulary of a large-scale model into blocks to obtain several plaintext blocks; generating an initialization vector based on the MAC address of the server to be deployed; randomly generating a first key; encrypting the plaintext blocks using a ciphertext block chaining mode based on the initialization vector and the first key to obtain several ciphertext blocks; encrypting the first key using a public key to obtain a second key; and sending the second key and the ciphertext blocks to the server to be deployed, enabling the server to decrypt the second key and the ciphertext blocks using its private key to obtain the vocabulary of the large-scale model and perform inference deployment. Using this invention, the security of large-scale models can be improved, effectively avoiding the leakage of source code during large-scale model migration and deployment, and preventing data from being tampered with or stolen during transmission.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Hardware-based data protection method

The application relates to the technical field of data processing, and particularly provides a hardware-based data protection method, aiming to solve the technical problem of poor software encryption effect in the prior art. The method comprises the following steps: based on a first module, a first public key, a first private key, a key plaintext and an initialization vector are generated; based on a preset second public key, a preset cipher suite and the first public key, additional verification data is obtained; based on the second public key and the first private key, a first symmetric key is obtained; based on the first symmetric key, the additional verification data and the initialization vector, the key plaintext is encrypted to obtain a negotiation result; and based on the key plaintext, data ciphertext is obtained by encrypting data plaintext to be protected. The hardware is used for encryption, thereby improving the security and operation efficiency; in each encryption process, the first public key, the first private key, the first key plaintext and the initialization vector are randomly generated by the hardware, thereby enhancing the forward security of the encryption process.
Owner:NIO TECH ANHUI CO LTD

Block cipher algorithm architecture, algorithm calling method and device and electronic equipment

The invention relates to a block cipher algorithm architecture, an algorithm calling method and device and electronic equipment. The algorithm architecture comprises a quantum security layer which is used for taking a quantum true random number generator as a key entropy source and generating an unpredictable initialization vector and a dynamic key seed based on a quantum optical effect; the hybrid encryption layer is used for encrypting a session key by adopting a hybrid encryption mechanism of post quantum cryptography and SM4 and using a public key algorithm based on lattice cryptography, generating a master key through an anti-quantum algorithm, and generating a sub-key sequence in combination with an SM4 round key expansion algorithm; the core algorithm layer is used for optimizing a round function, dynamically generating an S-box replacement table based on quantum random numbers through an implicit coding technology of dynamic S-box generation and white-box protection, carrying out implicit coding on XOR and shift operations in the round function and injecting redundant noise data; and the protocol adaptation layer is used for integrating a dynamic defense protocol. The encryption security can be improved, and the algorithm efficiency can be remarkably improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Method for protection against side-channel attacks

Method for protection against side-channel attacks. This method comprises: - the generation (144) of an initialization vector, then - the production (146) of a new mask from the generated initialization vector and a secret key, - the masking (148) of data to be written to an internal cache using the newly constructed mask to obtain masked data, - the storage (150), in the same word of the internal cache, of the masked data and the generated initialization vector, - the unmasking of the masked data comprises: - the extraction (162) of the initialization vector contained in the word, - the reconstruction (164) of the mask from the extracted initialization vector and the secret key, then - the unmasking (166) of the masked data using the newly reconstructed mask. Fig. 2
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

A method and device for realizing three-dimensional model software online encryption based on AES-GCM

ActiveCN119109625BSecure encryptionSecure decryptionModeling softwareInitialization vector
The application discloses a kind of based on AES-GCM implementation three-dimensional model software online encryption method and device.The method includes the following steps: first, obtain the front three-dimensional model software data, then format, then generate initial fingerprint code;Then using the AES key and initialization vector IV based on AES-GCM, initial fingerprint code is encrypted, and encrypted fingerprint code and authentication label are generated;AES key is obtained by crypto.subtle.generateKey encapsulation function;AES key, initialization vector IV and authentication label are all stored in the local file of front end;AES key, initialization vector IV and authentication label are called from local file, and encrypted fingerprint code is decrypted to obtain decrypted fingerprint code;Finally, the decrypted fingerprint code is compared with initial fingerprint code, to obtain the authorization of front three-dimensional model software data.The method can be completely based on front end without back end to carry out safe AES-GCM encryption and decryption, guarantee the data security of three-dimensional model software.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

File encryption and decryption method and device, electronic equipment and storage medium

The invention provides a file encryption and decryption method and device, electronic equipment and a storage medium, and belongs to the technical field of data security, and the method comprises the steps: carrying out the grouping encryption of a to-be-encrypted file based on a randomly generated initialization vector, a file hash value and the number of encryption times of the grouping encryption of the to-be-encrypted file; the file hash value is determined based on the file to be encrypted. According to the invention, on the basis of the file grouping encryption, the file grouping encryption is carried out not only based on the initialization vector, but also based on the file hash value and the encryption times of the to-be-encrypted file, so that the problem of initial vector attack existing in a standard grouping encryption mode can be solved, and the security strength of an encryption algorithm is improved.
Owner:CHINA MOBILE COMM GRP CO LTD +1

Industrial encryption communication method and system fusing national secret algorithm and dynamic key mechanism

The invention relates to the technical field of secure network communication, and discloses an industrial encryption communication method and system fusing a national cryptographic algorithm and a dynamic key mechanism, and the method comprises the steps: a transmitting end obtains a network layer data packet, analyzes a specific field of an IP head of the network layer data packet, and obtains a current timestamp; based on the specific field and the timestamp, a dynamic key sequence number is calculated through a preset key sequence number generation algorithm; extracting a corresponding encryption key and an initialization vector from a pre-stored key library which is the same as the receiving end according to the serial number; and encrypting the data load by using the CTR working mode of the SM4 algorithm, adding a timestamp to the head of the encrypted load, and sending the encrypted load. And the receiving end extracts the timestamp to perform timeliness verification, and calculates the same key sequence number based on the same field and the timestamp to complete decryption. The method realizes a one-time pad dynamic key mechanism, has the advantages of high encryption strength, good compatibility and the like, and is particularly suitable for an industrial control communication environment with high requirements on real-time performance and reliability.
Owner:DONGFANG ELECTRIC (CHENGDU) INNOVATION RES CO LTD +1