Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

120 results about "Initialization vector" patented technology

In cryptography, an initialization vector (IV) or starting variable (SV) is a fixed-size input to a cryptographic primitive that is typically required to be random or pseudorandom. Randomization is crucial for encryption schemes to achieve semantic security, a property whereby repeated usage of the scheme under the same key does not allow an attacker to infer relationships between segments of the encrypted message. For block ciphers, the use of an IV is described by the modes of operation. Randomization is also required for other primitives, such as universal hash functions and message authentication codes based thereon.

Industrial control system security auditing method and system

The invention relates to the technical field of security auditing, in particular to a security auditing method and system for an industrial control system, and the method comprises the following steps: aiming at a key control task, a communication task and a security task of a real-time operating system, collecting a period, a starting timestamp, a finishing timestamp, a central processing unit occupied time slice and peak memory usage amount data. According to the method, the period, timestamp, central processing unit occupation and memory usage data of a key task of a real-time operating system are collected, a task execution time boundary and a resource consumption envelope are set, and then an expected relation rule set of a task time sequence and resource consumption is constructed by applying historical data statistics and logic rule deduction; and meanwhile, the key length of symmetric and asymmetric encryption, initialization vector generation, hash algorithm selection, key derivation parameters and encryption operation context are stipulated, so that a comprehensive and specific ICS behavior specification baseline is established.
Owner:CHONGQING HUATAI ACCOUNTING FIRM (GENERAL PARTNERSHIP)

Intelligent variable frequency dimming method and system

The invention discloses an intelligent variable-frequency dimming method and system, and relates to the technical field of computer platform load balancing, and the method comprises the steps: establishing communication between a module and a gateway, loading a frequency mapping table, a duty ratio segmentation point, a safety threshold and a forbidden frequency point table, and generating an initialization vector in combination with parameters of a driver and a lamp; collecting current, voltage and optical brightness data at typical brightness points to form a matrix, calculating a risk value and marking a critical point, generating three-section type frequency mapping by combining segmentation points, and performing interpolation correction; and receiving a brightness instruction according to the mapping table to generate a PWM signal, performing slope limiting, edge shaping and micro-jitter frequency processing and outputting, and performing closed-loop frequency correction under real-time sampling. According to the method, by collecting multi-source data and introducing a stroboscopic risk model, critical point identification and three-section type frequency mapping are realized, and frequency continuity and stability are ensured by combining interpolation and forbidden frequency point constraint; on the basis, a PWM signal is generated and optimized, so that self-adaptive dimming is realized in a full-brightness interval.
Owner:SHANDONG BITTEL INTELLIGENT TECH CO LTD

Cryptographic authentication signatures for verification of streaming data

Systems and techniques are described for signing and verifying a data stream with an encryption signature. An example method includes determining, for a data block group, an initialization vector. The example method also includes generating, based at least in part on the data block group, encrypted hash data. The example method also includes determining an encryption signature based at least in part on the encrypted hash data, a private key, and the initialization vector. The example method also includes inserting the encryption signature into the data block group. The example method also includes causing transmission, by a network interface to a media server, of the data block group and the encryption signature. Finally, the example method includes causing verification, via the media server using a public key and synchronized data, that the data block group was generated by the computing device.
Owner:AMAZON TECH INC

Urban inspection data sharing method and device based on unmanned aerial vehicle

The invention discloses a city inspection data sharing method and device based on an unmanned aerial vehicle, and the method comprises the steps: firstly determining an inspection time period when the inspection data needs to be shared, and collecting the position, speed, signal and meteorological data set of the unmanned aerial vehicle in the time period according to a preset sampling frequency; after all the data sets are aligned through timestamps, features are extracted respectively to form multi-dimensional feature vectors; converting the multi-dimensional feature vector into a one-dimensional array, and generating a hash feature value through a hash algorithm in combination with a timestamp and a random number; extracting a master key and an authentication key from the hash feature value, generating an initialization vector based on the master key, binding the master key, the authentication key and a timestamp, and then distributing the three to a receiver; inspection data is divided into blocks, a number and a timestamp are added to each block, encryption is performed by using a master key and an initialization vector, an authentication tag is generated in combination with an authentication key, and a data packet is packaged and then transmitted. According to the invention, the problem of low security during routing inspection data sharing of the unmanned aerial vehicle in the prior art is solved.
Owner:YIKONG UAV TECHNOLOGY (JIANGXI) CO LTD

Memory systems and devices including examples of accessing memory and generating access codes using an authenticated stream cipher

Examples of systems and methods described herein provide for accessing memory devices and, concurrently, generating access codes using an authenticated stream cipher at a memory controller. For example, a memory controller may use a memory access request to, concurrently, perform translation logic and / or error correction on data associated with the memory access request; while also utilizing the memory address as an initialization vector for an authenticated stream cipher to generate an access code. The error correction may be performed subsequent to address translation for a write operation (or prior to address translation for a read operation) to improve processing speed of memory access requests at a memory controller; while the memory controller also generates the encrypted access code.
Owner:MICRON TECHNOLOGY INC

SM4-based data encryption transmission method, system and equipment

The invention provides a data encryption transmission method, system and device based on SM4, and belongs to the technical field of data encryption transmission. The method comprises the following steps: acquiring an encrypted fragmented data packet from front-end equipment; wherein the encrypted fragment data packet at least comprises a ciphertext fragment set, a timestamp and an environment feature hash value which are determined based on the network state value of the front-end equipment and the acquisition environment parameters. The number of ciphertext fragments in the ciphertext fragment set is in positive correlation with the network state value; matching the environment feature hash value with a preset environment feature hash library to determine whether a decryption parameter is generated or not according to a matching result; wherein the decryption parameters at least comprise a dynamic key and an initialization vector IV; if yes, generating decryption parameters according to the encrypted fragmented data packet; and decrypting each ciphertext fragment in the ciphertext fragment set based on the decryption parameters and a preset SM4 algorithm. Therefore, flexible, safe and stable data encryption transmission is realized in a water conservancy monitoring scene.
Owner:INSPUR SMART TECH INNOVATION (SHANDONG) CO LTD

A method and device for implementing high-speed operation of an algorithm based on a multi-level field cache

The application discloses a method and device for realizing high-speed operation of an algorithm based on a multi-level field cache, which comprises the following steps: a configuration management CPU sends algorithm parameters to an FPGA chip and saves the algorithm parameters in a RAM; a service processing CPU creates a handle and sends the handle to the configuration management CPU; the configuration management CPU generates a key number according to the handle; the configuration management CPU sends a key library to the FPGA chip; the service processing CPU sends a to-be-operated message to the FPGA chip; an algorithm scheduling module performs fragmentation judgment, and performs subsequent processing according to a sequence judgment result; a password operation module takes the received key, an initialization vector or an intermediate chain variable and the to-be-operated message as input, performs password operation, and outputs a calculation result and an operated intermediate chain variable; whether the to-be-operated message is the last data fragment is judged according to a tail fragment identifier, and subsequent processing is performed according to a tail fragment judgment result. The application can reduce the communication interface and CPU access times, realize high-speed operation of a password algorithm, and improve the overall performance of a password service system.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD

Data enhancement encryption method, system and equipment based on AES (Advanced Encryption Standard) and medium

The invention provides an AES (Advanced Encryption Standard)-based data enhancement encryption method, system and equipment and a medium, and belongs to the technical field of data security. The method comprises the following steps: receiving plaintext data to be encrypted and a password provided by a user; deriving a master key and an HMAC key from the password and the randomly generated salt value by using a key derivation function; randomly generating an initialization vector, and encrypting the plaintext data through the master key by using an AES encryption mode to obtain encrypted ciphertext data; performing message authentication code calculation on the ciphertext data, the initialization vector and the salt value through an HMAC key to generate an HMAC check value; and combining the salt value, the initialization vector, the ciphertext data and the HMAC verification value into a final output encrypted data packet. According to the method, a series of enhancement mechanisms such as strong key derivation, random salt values, message authentication codes and initialization vectors are introduced, so that the security and integrity of data are further improved.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Encryption method and device for dynamic data of unmanned aerial vehicle, and medium

The invention provides an encryption method and device for dynamic data of an unmanned aerial vehicle and a medium, and relates to the technical field of data encryption, and the method comprises the steps: dividing an airspace into a plurality of initial airspace grids according to a preset longitude interval and a preset latitude interval, and determining a target airspace grid corresponding to the dynamic data of the unmanned aerial vehicle; based on an AES-CBC encryption mode, using an AES key corresponding to the target airspace grid and the initialization vector to encrypt the dynamic data of the unmanned aerial vehicle; based on a preset access control strategy tree corresponding to the target airspace grid, encrypting the AES key and the initialization vector corresponding to the target airspace grid by using a CP-ABE encryption algorithm; the encryption result of the dynamic data of the unmanned aerial vehicle is obtained; according to the method, each initial airspace grid is used as an independent encryption and authorization unit, and fine-grained access control is realized through a hybrid encryption architecture, so that unauthorized access can be effectively prevented, and calculation, storage and transmission overhead caused by traditional multi-copy encryption is avoided.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

Dynamic encryption / decryption of genomic information

Examples are described for dynamically encrypting and / or decrypting a file formed of multiple blocks of ordered data. In one example, a method of dynamically encrypting a file to enable partial decryption of the file includes generating, using a secret key and one or more initialization vectors, a keystream for the multiple blocks of ordered data, encrypting the multiple blocks of ordered data of the file by performing a logical operation of the keystream with the multiple blocks of ordered data in a one-to-one correspondence, and building a file index of the file to identify location information of the multiple blocks of ordered data. The method may further include dynamically decrypting at least a portion of the file by decrypting at least one selected block of encrypted data of the file using a portion of the keystream, the portion of the keystream corresponding to the at least one selected block.
Owner:UNIV OF SOUTHERN CALIFORNIA +1

System and method for securing cryptographic key material

A method for operating secure computer processes includes storing a local encryption key in a register of a processor. The local encryption key is stored in a masked state. The method further includes receiving, from a memory communicating with the processor, an operational encryption key. The method includes encrypting the operational encryption key using the local encryption key and an initialization vector to generate an encrypted operation key. The local encryption key is unmasked prior to encrypting the operational encryption key. Further, the method includes storing the encrypted operational key, the initialization vector, and a verification hash value in the memory. The method includes decryption of symmetric operational keys directly to processor registers without using memory. The method includes decryption of asymmetric operational keys. In the method, the asymmetric key material is decrypted temporarily to memory and that memory is sanitized following the use of the key.
Owner:SKV TECHNOLOGY INC

LDPC encoder based on DVB-S2 protocol, transmitting terminal and test platform

The invention discloses an LDPC encoder based on a DVB-S2 protocol, a transmitting terminal and a test platform, and the LDPC encoder comprises an information bit matrix multi-port input RAM which is used for storing input information bits; the check matrix multi-port ROM is used for storing a check matrix; the accumulative sum matrix RAM is used for storing the accumulative sum matrix generated by the accumulative sum matrix calculation module; the check bit matrix RAM is used for storing a check bit matrix; the check matrix calculation module reads a check matrix from the check matrix multi-port ROM, and the check matrix is converted into a cyclic shift matrix through preprocessing; the accumulative sum matrix calculation module is used for reading information bits from the information bit matrix multi-port input RAM, executing loop right shift and accumulative operation, and calculating to obtain an accumulative sum matrix; and the check bit matrix initialization module is used for calculating a check bit matrix initialization vector according to a calculation result of the accumulation and matrix calculation module.
Owner:FUDAN UNIVERSITY

Video encryption transmission method, video decryption output method and device

The invention provides a video encryption transmission method and device and a video decryption output method and device. The video encryption transmission method comprises the following steps: constructing a security parameter set according to an encrypted video encryption key and an initialization vector of an image group; performing XOR operation on the first L-1 bytes of the original data byte stream by adopting the stream key to obtain encrypted byte stream data; setting a network abstraction layer header for each network abstraction layer unit after the image group is processed, wherein the network abstraction layer header at least comprises original coding standard information and encryption state information; performing hash signature processing on the encrypted byte stream data of the image group to generate signature data, and packaging the signature data into an authentication network abstraction layer unit; packaging the security parameter set, the network abstraction layer unit provided with the network abstraction layer head, the authentication network abstraction layer unit and the original parameter set of the image group according to the transmission sequence of the original code stream of the image group to obtain an encrypted video code stream; and sending the encrypted video code stream to a receiver.
Owner:BEIJING ZHONGYU WANTONG TECH CO LTD

Distributed data content protection

Systems and methods are described for encrypting and decrypting data in a distributed storage environment. Such systems and methods for encryption may divide a data payload into slices, the slices including a first slice and a subsequent slice, employ a content encryption key and an initialization vector, encrypt the first slice using the content encryption key and the initialization vector, generate a subsequent initialization vector for the subsequent slice based upon the initialization vector and the unencrypted content of the first slice, and encrypt the subsequent slice using the subsequent initialization vector and the content encryption key. The systems and methods may then generate a list of the encrypted slices into which the data payload has been generated, and publish to a secure storage location, the slice list, the content encryption key and the initialization vector for the first slice in the slice list, with the slices outputted to the distributed storage environment. Systems and methods for decryption may receive, from a secure storage location, a slice list, a content encryption key, and an initialization vector, determine the encrypted slices to be received from the distributed storage environment. The systems and methods may receive, from the distributed storage environment, at least encrypted first slice and the encrypted subsequent slice, and decrypt the first slice using the content encryption key and the initialization vector, to generate a decrypted first slice, and generate a subsequent initialization vector for the subsequent slice based upon the initialization vector and the decrypted first slice, decrypt the subsequent slice using the subsequent initialization vector and the content encryption key, and combine the first slice and the subsequent slice into a data payload.
Owner:ADEIA GUIDES INC

Secure communication protocol for communication devices

A method for transmitting secured Ethernet frames on a communication line, the method including the following in a transmitter module: receiving an Ethernet frame comprising payload data from a network layer; retrieving a secure policy, defining the type of security to be applied to the Ethernet frame; producing an initialization vector based on an encryption counter and a physical address of the transmitter module; creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector; adding the secure policy, the initialization vector and the authentication tag to the payload data to create a secured Ethernet frame; and sending the secured Ethernet frame to a data link layer for transmission on the communication line.
Owner:SCHNEIDER ELECTRIC IND SAS

Unique initialization vectors for secure communication over multipath networks

Techniques described herein can allocate respective unique secure channel identifiers (SCIs) to respective uplink encryptor interfaces which provide intersite connectivity over multipathing internet protocol (IP) networks between a first data center site and a second data center site. A respective uplink encryptor interface can then use the unique SCI allocated thereto, along with a packet number counter value to encrypt and generate an integrity check value for at least a portion of a packet. The encryption can comprise using the SCI and the packet number counter value to generate a unique packet initialization vector for the packet, which is then used to encrypt and integrity protect the packet. The respective uplink encryptor interface can send the encrypted packet via a tunnel to a second data center site via a secure communication channel spanning across multiple encryptors and multiple decryptors. The encrypted packet can be decrypted at the second data center site and forwarded along to its destination within the second data center site.
Owner:CISCO TECHNOLOGY INC

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Colorful QR code generation method and system based on AES-RSA dual encryption

The invention discloses a color QR code generation method and system based on AES-RSA dual encryption, and relates to the technical field of data encryption, and the method comprises the steps: carrying out the byte filling and segmentation of a preprocessing data package; performing AES encryption operation on each data block based on the AES key and the initialization vector to obtain a complete AES ciphertext; filling the AES key packet by adopting an OAEP filling method; encrypting the key packet filled with the OAEP by adopting an RSA public key to generate an identifier; obtaining a hybrid ciphertext packet based on the complete AES ciphertext, the key packet and the identifier; the mixed ciphertext packet is divided into three equal parts, check codes are added, three sections of mixed ciphertext data with the check codes are obtained, priority coding is carried out, and a QR code dot matrix is generated; and obtaining a final color QR code based on the color mapping function and the QR code dot matrix. According to the invention, the security of data transmission is improved, and the information capacity of data transmission is increased.
Owner:GUILIN UNIVERSITY OF TECHNOLOGY

An LDPC encoder, transmitter and test platform based on the DVB-S2 protocol

The present invention discloses an LDPC encoder, a transmitting end and a test platform based on the DVB-S2 protocol. The LDPC encoder includes an information bit matrix multi-port input RAM for storing input information bits; a check matrix multi-port ROM for storing the check matrix; an accumulated sum matrix RAM for storing the accumulated sum matrix generated by a accumulated sum matrix calculation module; a check bit matrix RAM for storing the check bit matrix; a check matrix calculation module for reading the check matrix from the check matrix multi-port ROM, wherein the check matrix is converted into a cyclic shift matrix after preprocessing; a accumulated sum matrix calculation module for reading the information bits from the information bit matrix multi-port input RAM, performing cyclic right shift and accumulation operations, and calculating to obtain the accumulated sum matrix; and a check bit matrix initialization module for calculating a check bit matrix initialization vector according to the calculation result of the accumulated sum matrix calculation module.
Owner:FUDAN UNIVERSITY

Data table lookup method and device, equipment, storage medium and computer program product

The invention discloses a data table lookup method and device, equipment, a storage medium and a computer program product, and relates to the technical field of data lookup, the method comprises the following steps: when a data table query statement is received, converting the data table query statement into a semantic vector; performing similarity matching on the semantic vector and a table vector set and a non-table vector set in a to-be-queried database to obtain a first similarity set and a second similarity set; the initialization vector is normalized based on the first similarity set and the second similarity set, a normalized vector is obtained, and the initialization vector is constructed based on the knowledge graph of the database to be queried; and calculating a correlation score, corresponding to the data table query statement, of each component in the normalized vector, and searching a target data table from the to-be-queried database based on the correlation score. Based on the method, deep mining and relational network construction are performed on the to-be-queried database, so that the target data table can be accurately searched from the database.
Owner:CHINA MERCHANTS BANK

Service and security enhancement of communication services

Authorization for access to an application server and associated communication service can be desirably managed. When a device attempts to access an application server and service, an authorization server generates an encrypted token, comprising device identifier information, and communicates the token to the device. The device communicates the token to the application server. The application server communicates the token to the authorization server. The authorization server determines whether the device is validated to access the application server and service based on the encrypted token, private decryption key, and initialization vector, and based on subscriber-related information. The authorization server does not share the private decryption key or initialization vector with the application server. If validated, the authorization server communicates validation-related information, including a permitted portion of subscriber-related information, to the application server. If not validated, the authorization server communicates not-validated information to the application server.
Owner:AT&T INTELLECTUAL PROPERTY I L P

AES-based data enhancement encryption method, system, device and medium

The present invention provides a data enhancement encryption method, system, device, and medium based on AES, belonging to the field of data security technology. The method comprises: receiving plaintext data to be encrypted and a password provided by a user; deriving a master key and an HMAC key from the password and a randomly generated salt value using a key derivation function; randomly generating an initialization vector, and encrypting the plaintext data using the master key using the AES encryption mode to obtain encrypted ciphertext data; performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value using the HMAC key to generate an HMAC check value; and combining the salt value, the initialization vector, the ciphertext data, and the HMAC check value into a final output encrypted data packet. The present invention further improves the security and integrity of data by introducing a series of enhancement mechanisms such as strong key derivation, random salt value, message authentication code, and initialization vector.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Transmitting and receiving method, communicating device, and local area network

The present disclosure relates to a method for transmitting data by a communicating device on a communication channel, wherein the transmitting method comprises, for each temporal cycle:determining, by the communicating device, a secured data frame based on the data to be transmitted,transmitting, by the communicating device, the secured data frame on the communication channel,wherein each secured data frame includes secured content determined by using an initialization vector, wherein the initialization vector has a lifetime associated thereto, the lifetime being greater than or equal to a plurality of cycle periods, wherein the initialization vector is not modified when the data to be transmitted is identical to the data transmitted in the previous temporal cycle provided the lifetime of the initialization vector has not expired.
Owner:MITSUBISHI ELECTRIC CORP

Symmetrical encryption security reinforcement method, device, equipment, medium and program product

The invention discloses a symmetric encryption security reinforcement method, device and equipment, a medium and a program product, and the method comprises the steps: carrying out the first-round encryption processing of original data read from a second node through employing an initialization vector and a first secret key sent by the second node, and obtaining first encrypted data; segmenting the first encrypted data and the first secret key to obtain a plurality of data blocks and a plurality of second secret keys; the plurality of data blocks and the plurality of second secret keys are distributed to a plurality of third nodes, so that the third nodes encrypt the data blocks based on third secret keys generated by the second secret keys to generate second encrypted data; and finally, combining the second encrypted data sent by the plurality of third nodes to obtain third encrypted data, thereby realizing distributed multi-round asynchronous encryption of the original data, including the first-round encryption of the first node in the chain and the distributed multi-round encryption of the third node in the chain, thereby effectively improving the security, reliability and privacy of symmetric encryption.
Owner:CHINA MOBILE INTERNET CO LTD +1

APP identification method and device for TG framework, medium and product

The embodiment of the invention relates to the technical field of flow identification, and discloses an APP identification method and device for a TG framework, a medium and a product. TCP flow is collected; extracting a key and an initialization vector from a first loaded uplink packet of the TCP flow; according to the secret key and the initialization vector, an aes algorithm is adopted to decrypt the data of the first uplink packet with the load, and updakeyid is obtained; according to the secret key and the initialization vector, an aes algorithm is adopted to decrypt data of the first downlink packet with the load, and dnaeskeyid is obtained; and when the updakeyyid is the same as the dnaeskeyyid, judging that the TCP flow is an APP (Application) which adopts a TG (Triggered Generation) framework, and when the updaeskeyyid is the same as the dnaeskeyyid. The technical problem of TG framework application traffic identification can be at least solved.
Owner:WUHAN BOYIXUN INFORMATION TECH CO LTD

A data privacy protection encryption retrieval method and system and a storage medium

This invention provides an encrypted retrieval method, system, and storage medium for data privacy protection. The retrieval method includes: dividing document set keywords into low-frequency and high-frequency subsets according to a frequency threshold; generating deterministic tokens for keywords using a key-based pseudo-random function and storing the correspondence between tokens and keyword types; for low-frequency keywords, constructing a static primary index using a minimum perfect hash structure, mapping tokens to hash buckets, and storing pointers to a list of encrypted document identifiers; for high-frequency keywords, constructing a dynamically updated secondary index using encrypted key-value storage, storing the mapping between tokens and encrypted document identifiers; during retrieval, the user generates a deterministic token for the keyword to be searched and uploads it as a trapdoor; the server queries the primary and secondary indexes according to the type; and the document identifiers generate a key stream using a derived symmetric key and an initialization vector, and are then XORed bitwise.
Owner:BEIJING DEXUN AVIATION SERVICE CO LTD

Method, device, medium and program product for constructing initial vector based on combination counter

The present invention relates to the field of information security technology and provides a method, device, medium, and program product for constructing an initialization vector (IV) based on a combination counter. The method comprises: two communicating parties agreeing in advance on a padding number; and using the combination counter and the padding number to jointly construct an initialization vector (IV) for encryption and decryption. The method proposed in the present invention is a special method based on multiple combination digital counters, such as a cycle counter and a communication counter. In combination with channel transmission resource requirements, the cycle counter and the communication counter are represented by reasonable calculations. This method ensures one-time, one-key system information transmission and meets system security communication requirements while utilizing fewer communication resources and without compromising system lifespan. The method has broad application prospects, particularly in wireless system applications where channel transmission resources are relatively limited.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Distributed storage data protection method for cryptographic algorithm dynamic reconstruction

The invention discloses a distributed storage data protection method for cryptographic algorithm dynamic reconstruction, which relates to the technical field of data encryption, and comprises the following steps of: determining an algorithm capability set and an alternating window before data writing, calculating path hash and generating an algorithm reconstruction vector, deriving a session key from a root key and signing and issuing a key algorithm capsule, forming write context data; the method comprises the following steps of: performing deterministic fragmentation on data by using a write-in context, generating an abstract from the tail part of a fragment, performing hash synthesis on the abstract and a path to obtain an initialization vector, encrypting a head part by using a path-sensitive authentication encryption algorithm, protecting the rest part by using a pseudo-random mask, and generating a fragment ciphertext list and an original index table; according to the method, after deterministic fragmentation, an initialization vector is synthesized through a tail abstract and path hash, path-sensitive authentication encryption and body segment pseudo-random mask are executed, and fragmentation-level anti-replay and high-throughput data encryption is achieved.
Owner:SUZHOU GUANWEN STORAGE TECH CO LTD

Recommendation method for refracturing target well based on TRA-SR architecture

The invention relates to the technical field of reservoir yield increase and transformation, in particular to a TRA-SR architecture-based refracturing target well recommendation method, which comprises the following steps of: collecting production data of a to-be-fractured low-efficiency well, a corresponding expert score and data of a refractured well with a good production condition as a target well construction data set; through a Transform embedding layer, each well is converted into a dense initialization vector, and position information is added to identify a sequence relation; the expert score is integrated into a multi-head self-attention mechanism of a Transform encoder part, and global preference is calculated; calculating the similarity between the to-be-fractured inefficient well and the re-fractured well as local preference; the global preference and the local preference are integrated into mixed preference through a linear layer; and after the mixing preference is obtained, a comprehensive score of the to-be-fractured low-efficiency well is calculated to recommend a well suitable for repeated fracturing. According to the method, the target well suitable for refracturing can be effectively evaluated and screened, and the method is beneficial to promoting treatment of low-efficiency wells, restoring the productivity and improving the recovery efficiency.
Owner:CHINA NAT PETROLEUM CORP +1