Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Initialization vector" patented technology

In cryptography, an initialization vector (IV) or starting variable (SV) is a fixed-size input to a cryptographic primitive that is typically required to be random or pseudorandom. Randomization is crucial for encryption schemes to achieve semantic security, a property whereby repeated usage of the scheme under the same key does not allow an attacker to infer relationships between segments of the encrypted message. For block ciphers, the use of an IV is described by the modes of operation. Randomization is also required for other primitives, such as universal hash functions and message authentication codes based thereon.

Encryption method and device for dynamic data of unmanned aerial vehicle, and medium

The invention provides an encryption method and device for dynamic data of an unmanned aerial vehicle and a medium, and relates to the technical field of data encryption, and the method comprises the steps: dividing an airspace into a plurality of initial airspace grids according to a preset longitude interval and a preset latitude interval, and determining a target airspace grid corresponding to the dynamic data of the unmanned aerial vehicle; based on an AES-CBC encryption mode, using an AES key corresponding to the target airspace grid and the initialization vector to encrypt the dynamic data of the unmanned aerial vehicle; based on a preset access control strategy tree corresponding to the target airspace grid, encrypting the AES key and the initialization vector corresponding to the target airspace grid by using a CP-ABE encryption algorithm; the encryption result of the dynamic data of the unmanned aerial vehicle is obtained; according to the method, each initial airspace grid is used as an independent encryption and authorization unit, and fine-grained access control is realized through a hybrid encryption architecture, so that unauthorized access can be effectively prevented, and calculation, storage and transmission overhead caused by traditional multi-copy encryption is avoided.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

Video encryption transmission method, video decryption output method and device

The invention provides a video encryption transmission method and device and a video decryption output method and device. The video encryption transmission method comprises the following steps: constructing a security parameter set according to an encrypted video encryption key and an initialization vector of an image group; performing XOR operation on the first L-1 bytes of the original data byte stream by adopting the stream key to obtain encrypted byte stream data; setting a network abstraction layer header for each network abstraction layer unit after the image group is processed, wherein the network abstraction layer header at least comprises original coding standard information and encryption state information; performing hash signature processing on the encrypted byte stream data of the image group to generate signature data, and packaging the signature data into an authentication network abstraction layer unit; packaging the security parameter set, the network abstraction layer unit provided with the network abstraction layer head, the authentication network abstraction layer unit and the original parameter set of the image group according to the transmission sequence of the original code stream of the image group to obtain an encrypted video code stream; and sending the encrypted video code stream to a receiver.
Owner:BEIJING ZHONGYU WANTONG TECH CO LTD

Secure communication protocol for communication devices

A method for transmitting secured Ethernet frames on a communication line, the method including the following in a transmitter module: receiving an Ethernet frame comprising payload data from a network layer; retrieving a secure policy, defining the type of security to be applied to the Ethernet frame; producing an initialization vector based on an encryption counter and a physical address of the transmitter module; creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector; adding the secure policy, the initialization vector and the authentication tag to the payload data to create a secured Ethernet frame; and sending the secured Ethernet frame to a data link layer for transmission on the communication line.
Owner:SCHNEIDER ELECTRIC IND SAS

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

A data privacy protection encryption retrieval method and system and a storage medium

This invention provides an encrypted retrieval method, system, and storage medium for data privacy protection. The retrieval method includes: dividing document set keywords into low-frequency and high-frequency subsets according to a frequency threshold; generating deterministic tokens for keywords using a key-based pseudo-random function and storing the correspondence between tokens and keyword types; for low-frequency keywords, constructing a static primary index using a minimum perfect hash structure, mapping tokens to hash buckets, and storing pointers to a list of encrypted document identifiers; for high-frequency keywords, constructing a dynamically updated secondary index using encrypted key-value storage, storing the mapping between tokens and encrypted document identifiers; during retrieval, the user generates a deterministic token for the keyword to be searched and uploads it as a trapdoor; the server queries the primary and secondary indexes according to the type; and the document identifiers generate a key stream using a derived symmetric key and an initialization vector, and are then XORed bitwise.
Owner:BEIJING DEXUN AVIATION SERVICE CO LTD

Distributed storage data protection method for cryptographic algorithm dynamic reconstruction

The invention discloses a distributed storage data protection method for cryptographic algorithm dynamic reconstruction, which relates to the technical field of data encryption, and comprises the following steps of: determining an algorithm capability set and an alternating window before data writing, calculating path hash and generating an algorithm reconstruction vector, deriving a session key from a root key and signing and issuing a key algorithm capsule, forming write context data; the method comprises the following steps of: performing deterministic fragmentation on data by using a write-in context, generating an abstract from the tail part of a fragment, performing hash synthesis on the abstract and a path to obtain an initialization vector, encrypting a head part by using a path-sensitive authentication encryption algorithm, protecting the rest part by using a pseudo-random mask, and generating a fragment ciphertext list and an original index table; according to the method, after deterministic fragmentation, an initialization vector is synthesized through a tail abstract and path hash, path-sensitive authentication encryption and body segment pseudo-random mask are executed, and fragmentation-level anti-replay and high-throughput data encryption is achieved.
Owner:SUZHOU GUANWEN STORAGE TECH CO LTD

Quantum block cipher resisting coprocessor for computer monitoring system and operation method

The invention discloses an anti-quantum block cipher coprocessor operation method for a computer monitoring system, and the method comprises the following steps: S1, loading data to generate a random number and a secret key, and splicing the random number and the secret key with a preset initialization vector to generate an input state; s2, receiving the associated parameters and the plaintext, and performing preprocessing to generate grouping mask shares; s3, performing parallel encryption on the grouped mask shares based on an input state to generate a plurality of mask ciphertexts and mask authentication tags; and S4, performing linear reconstruction on the mask ciphertext to finally run to obtain a complete ciphertext, decomposing plaintext data into a plurality of mask shares for parallel processing, effectively diluting data structure features, and fundamentally cutting off a way of acquiring key information by an attacker through power consumption analysis. Compared with the prior art, the parallel computing advantage of reconfigurable hardware is fully utilized, efficient execution of cryptographic operation is achieved, the whole data processing process is completed in the register, and the influence of memory access delay on system performance is remarkably reduced.
Owner:HANGZHOU HUADIAN BANSHAN POWER GENERATION

An encryption method, device and medium for dynamic data of a UAV

The application provides an encryption method, device and medium for unmanned aerial vehicle dynamic data, and relates to the technical field of data encryption. The method divides airspace into a plurality of initial airspace grids according to a preset longitude interval and a preset latitude interval, and determines a target airspace grid corresponding to the unmanned aerial vehicle dynamic data. Based on an AES-CBC encryption mode, the unmanned aerial vehicle dynamic data is encrypted using an AES key and an initialization vector corresponding to the target airspace grid. Based on a preset access control strategy tree corresponding to the target airspace grid, the AES key and the initialization vector corresponding to the target airspace grid are encrypted using a CP-ABE encryption algorithm. Thus, an encryption result of the unmanned aerial vehicle dynamic data is obtained. Each initial airspace grid is taken as an independent encryption and authorization unit, and fine-grained access control is realized through a hybrid encryption architecture, which can effectively prevent unauthorized access and avoid the calculation, storage and transmission overhead caused by traditional multi-copy encryption.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

A method for processing financial data with improved security

This invention discloses a method for improving the confidentiality of financial data processing. In the field of information security technology, the method automatically identifies the source department and data type based on the submitter information of the financial data, determines the confidentiality level of the data using a confidentiality level rating table, and dynamically parses the key length and arrangement rules accordingly. It uses the characterization conversion results of the submitter's account and submission time, along with a random string, to perform multi-source fusion to construct a high-entropy basic key. After being hosted by a hardware security module, this key is intercepted to form the final encryption key, ensuring its unpredictability and security. An encryption algorithm combined with a random initialization vector is used to encrypt the original data text, ensuring the confidentiality and integrity of the data. The encrypted data is segmented according to the key length, generating a random number sequence and binding it to the data block. The number mapping relationship is stored on the blockchain. After being encapsulated with a unique identifier, the data block is randomly shuffled and further divided, and finally distributed and stored in the cloud.
Owner:JINAN JUSHI INFORMATION TECH CO LTD

A large model inference deployment method, system, device, storage medium and product

This invention discloses a method, system, device, storage medium, and product for deploying large-scale model inference. The method involves dividing the vocabulary of a large-scale model into blocks to obtain several plaintext blocks; generating an initialization vector based on the MAC address of the server to be deployed; randomly generating a first key; encrypting the plaintext blocks using a ciphertext block chaining mode based on the initialization vector and the first key to obtain several ciphertext blocks; encrypting the first key using a public key to obtain a second key; and sending the second key and the ciphertext blocks to the server to be deployed, enabling the server to decrypt the second key and the ciphertext blocks using its private key to obtain the vocabulary of the large-scale model and perform inference deployment. Using this invention, the security of large-scale models can be improved, effectively avoiding the leakage of source code during large-scale model migration and deployment, and preventing data from being tampered with or stolen during transmission.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Block cipher algorithm architecture, algorithm calling method and device and electronic equipment

The invention relates to a block cipher algorithm architecture, an algorithm calling method and device and electronic equipment. The algorithm architecture comprises a quantum security layer which is used for taking a quantum true random number generator as a key entropy source and generating an unpredictable initialization vector and a dynamic key seed based on a quantum optical effect; the hybrid encryption layer is used for encrypting a session key by adopting a hybrid encryption mechanism of post quantum cryptography and SM4 and using a public key algorithm based on lattice cryptography, generating a master key through an anti-quantum algorithm, and generating a sub-key sequence in combination with an SM4 round key expansion algorithm; the core algorithm layer is used for optimizing a round function, dynamically generating an S-box replacement table based on quantum random numbers through an implicit coding technology of dynamic S-box generation and white-box protection, carrying out implicit coding on XOR and shift operations in the round function and injecting redundant noise data; and the protocol adaptation layer is used for integrating a dynamic defense protocol. The encryption security can be improved, and the algorithm efficiency can be remarkably improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

A method and device for realizing three-dimensional model software online encryption based on AES-GCM

ActiveCN119109625BSecure encryptionSecure decryptionModeling softwareInitialization vector
The application discloses a kind of based on AES-GCM implementation three-dimensional model software online encryption method and device.The method includes the following steps: first, obtain the front three-dimensional model software data, then format, then generate initial fingerprint code;Then using the AES key and initialization vector IV based on AES-GCM, initial fingerprint code is encrypted, and encrypted fingerprint code and authentication label are generated;AES key is obtained by crypto.subtle.generateKey encapsulation function;AES key, initialization vector IV and authentication label are all stored in the local file of front end;AES key, initialization vector IV and authentication label are called from local file, and encrypted fingerprint code is decrypted to obtain decrypted fingerprint code;Finally, the decrypted fingerprint code is compared with initial fingerprint code, to obtain the authorization of front three-dimensional model software data.The method can be completely based on front end without back end to carry out safe AES-GCM encryption and decryption, guarantee the data security of three-dimensional model software.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

File encryption and decryption method and device, electronic equipment and storage medium

PendingCN121508799AEncryption apparatus with shift registers/memoriesAttackInitialization vector
The invention provides a file encryption and decryption method and device, electronic equipment and a storage medium, and belongs to the technical field of data security, and the method comprises the steps: carrying out the grouping encryption of a to-be-encrypted file based on a randomly generated initialization vector, a file hash value and the number of encryption times of the grouping encryption of the to-be-encrypted file; the file hash value is determined based on the file to be encrypted. According to the invention, on the basis of the file grouping encryption, the file grouping encryption is carried out not only based on the initialization vector, but also based on the file hash value and the encryption times of the to-be-encrypted file, so that the problem of initial vector attack existing in a standard grouping encryption mode can be solved, and the security strength of an encryption algorithm is improved.
Owner:CHINA MOBILE COMM GRP CO LTD +1

Industrial encryption communication method and system fusing national secret algorithm and dynamic key mechanism

The invention relates to the technical field of secure network communication, and discloses an industrial encryption communication method and system fusing a national cryptographic algorithm and a dynamic key mechanism, and the method comprises the steps: a transmitting end obtains a network layer data packet, analyzes a specific field of an IP head of the network layer data packet, and obtains a current timestamp; based on the specific field and the timestamp, a dynamic key sequence number is calculated through a preset key sequence number generation algorithm; extracting a corresponding encryption key and an initialization vector from a pre-stored key library which is the same as the receiving end according to the serial number; and encrypting the data load by using the CTR working mode of the SM4 algorithm, adding a timestamp to the head of the encrypted load, and sending the encrypted load. And the receiving end extracts the timestamp to perform timeliness verification, and calculates the same key sequence number based on the same field and the timestamp to complete decryption. The method realizes a one-time pad dynamic key mechanism, has the advantages of high encryption strength, good compatibility and the like, and is particularly suitable for an industrial control communication environment with high requirements on real-time performance and reliability.
Owner:DONGFANG ELECTRIC (CHENGDU) INNOVATION RES CO LTD +1

Decryption and encryption processing method of secondary development script, electronic device and medium

This invention relates to the field of electronic design automation (EDA) technology, and more particularly to a method, electronic device, and medium for encrypting and decrypting secondary development scripts. The method includes: S1, acquiring the secondary development script from an EDA tool and encrypting it to generate a script ciphertext data block; S2, packaging the script ciphertext data block, encryption algorithm identifier, and initialization vector into an encrypted script file; S3, setting a decryption loader within the EDA tool, including a hook function, and storing the decryption key locally within the EDA tool; S4, receiving a script import request, and the decryption loader intercepting the script import request by calling the hook function; S5, the decryption loader reading and identifying the script file in the import request, and if it is an encrypted script file, obtaining the decryption key and decrypting the encrypted script file to restore the secondary development script. This invention improves the security of secondary development scripts.
Owner:BEIJING NORI INTEGRATED CIRCUIT DESIGN CO LTD +2

Data encryption method and device, equipment and storage medium

The invention discloses a data encryption method and device, equipment and a storage medium, and relates to the technical field of data encryption. The method comprises the following steps: acquiring a to-be-encrypted data block and an initial key and an initialization vector of the to-be-encrypted data block, and caching the to-be-encrypted data block to a memory; determining an encryption algorithm corresponding to the to-be-encrypted data block, and generating a plurality of rounds of sub-keys corresponding to the to-be-encrypted data block based on the encryption algorithm and the initial key; when the data volume of the memory reaches a preset threshold value, processing each to-be-encrypted data block cached in the memory based on the initialization vector, and distributing each processed to-be-encrypted data block to each algorithm IP core in an idle state; and controlling each algorithm IP core in an idle state to perform multiple rounds of encryption operation based on the allocated processed data block to be encrypted and the corresponding multiple rounds of sub-keys, and generating ciphertext data. According to the invention, the time delay of processing the encryption task is reduced, and the throughput rate of data encryption processing is improved.
Owner:GUANGZHOU WANXIETONG INFORMATION TECH CO LTD

Stateless multi-provider ai game master system with transaction-based context reconstruction

PendingUS20260145077A1Video gamesLinguistic modelMegabyte
A stateless artificial intelligence game master system and method enables scalable, provider-agnostic interactive game experiences. The system comprises a stateless game server processing requests without persistent session state, a provider-agnostic AI orchestration engine supporting automatic failover between multiple language model providers, a context reconstruction module dynamically rebuilding game context from transaction logs, and a real-time integration module enforcing game mechanics without state persistence. The architecture achieves memory efficiency of approximately 16 kilobytes per session compared to 10+ megabytes for stateful implementations, enabling horizontal scaling without session affinity requirements. The system supports graceful degradation through template-based fallback when AI providers are unavailable. Security features include AES-256-GCM encryption of API credentials with session-specific initialization vectors. The invention addresses limitations of existing stateful AI game systems including memory accumulation, single-provider dependency, and session affinity requirements.
Owner:BINARY KINETICS LLC

A residual network-based sequential cipher register differential discriminator

A serial cipher register differential discriminator based on residual networks includes the following steps: 1) Dataset generation: For serial cipher algorithms, training samples containing fixed differences (label 1) and random differences (label 0) are generated. The data is loaded into the state register using the key and initialization vector, and after a warm-up round, concatenated input data of length 2M is generated; 2) Feature extraction and preprocessing: Linear transformation and batch normalization are performed using embedding layers to reshape the data into a format suitable for convolutional processing, and initial features are extracted using a 1D convolutional neural network; 3) Residual network architecture: Multi-layer residual blocks are designed, employing different dilation rates (2 for odd positions and 1 for even positions) to capture multi-scale contextual information, supporting 1-10 configurable residual blocks; 4) Classification prediction: Binary classification is achieved through adaptive average pooling, fully connected layers, and the Softmax activation function, with a threshold of 0.51 used to determine true differences and random differences.
Owner:GUILIN UNIV OF ELECTRONIC TECH

A video privacy protection method, a video decryption method and related devices

This application provides a video privacy protection method, a video decryption method, and related apparatus. The video encryption device uses an initialization vector and an encryption key to encrypt video frames containing privacy information in the original video, thereby achieving privacy protection. During the compression encoding of the privacy-protected video, the video encryption device uses a preset password to encrypt the initialization vector and / or the encryption key, and writes the encrypted parameter data into the video encoded data. On the one hand, for unauthorized attackers who do not know the preset password, they cannot accurately reconstruct the original video, thus further ensuring information security. On the other hand, for authorized users with the preset password, they can utilize the complete reversibility of encryption and decryption to accurately decrypt the lossless compressed encoded data, accurately reconstructing the original video, achieving reversible video privacy protection.
Owner:E SURFING VISION TECHNOLOGY CO LTD

Safe communication authentication method for electric energy meter

The invention discloses a secure communication authentication method for an electric energy meter, and aims to solve the problems that only link encryption is carried out in a multi-level network from an electric meter to a collector to a master station, the collector is visible and changeable, and packets are easy to lose in small-frame fragmentation. According to the method, the entity proof token and the mixed public key are packaged and bound in a hard manner, the key tree is constructed from the object level to the fragment level, the Merkel fragment commitment is used for generating the fragment level initialization parameter and the authentication related data, and the authentication encryption algorithm with the synthesis initialization vector characteristic is used for encryption and integrity protection. And meanwhile, a trusted execution environment monotonic counter is used for preventing rollback, and a system type forward error correction enhancement recovery capability is introduced, so that the technical effects of real end-to-end authentication and encryption, fragment-level insertion modification prevention, rearrangement prevention, truncation prevention, whole message consistency verification and adaptation to out-of-order and packet loss scenes are realized.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Secure access to vehicle electronic control unit (ECU)

A method of supporting secure access to an electronic control unit (ECU) of a vehicle may comprise receiving, from a diagnostic tool connected to the vehicle, encrypted data including an ECU address corresponding to the ECU, vehicle identification information of the vehicle, and a security seed, decrypting the encrypted data, retrieving, from a database, an initialization vector based on the ECU address and the vehicle identification information, calculating a security key based on the initialization vector and the security seed using an application programming interface (API) associated with an original equipment manufacturer (OEM) of the ECU, encrypting the security key, and sending the encrypted security key to the diagnostic tool to be decrypted and used by the diagnostic tool to gain secure access to the ECU.
Owner:INNOVA ELECTRONICS CORP

Data migration using counter hashing

Techniques described herein are directed toward a counter hash generation scheme. One embodiment includes a method for counter hash generation. The method includes a device receiving an instruction to transmit an artifact from a source system to a target system, the artifact comprising a plurality of blocks. The device receives a block from the source system. The device generates an initialization vector based at least in part on the artifact. The device generates a nonce based at least in part on the initialization vector and a block value, each block being assigned a respective block value by a counter. The device generates a combined data instance based at least in part on a combination of the nonce, data of the block, and a length of the block. The device generates a hash of the combined data instance. The device transmits the hash and the block to the target system.
Owner:ORACLE INT CORP

A lightweight encryption communication method between an intelligent fusion terminal and an electric energy meter

The present application relates to the field of digital information transmission, and particularly relates to a lightweight encryption communication method between an intelligent fusion terminal and an electric energy meter, which comprises the following steps: first, collecting background electromagnetic noise energy, equivalent impedance phase and inter-harmonic amplitude of a power grid line to form a multi-dimensional feature vector; then, quantizing the vector into an environment fingerprint, deriving a session key and an initialization vector based on the environment fingerprint and a cloud, and encrypting business data such as electric energy measurement values; then, calculating a comprehensive disturbance index and comparing the comprehensive disturbance index with a dynamic threshold value, and triggering key update when the power grid disturbance exceeds the threshold value; finally, the cloud decrypts and restores the encrypted data packet by querying the stored session key. The present application realizes dynamic binding of the encryption key and the physical environment of the power grid, thereby ensuring communication security and significantly reducing system overhead.
Owner:HANGZHOU XILI INTELLIGENT TECH CO LTD

An AES file confusion encryption system based on dynamic slice reorganization

PendingCN122394766AComputer hardwareCiphertext
This invention discloses an AES file obfuscation and encryption method, apparatus, system, storage medium, and computer program product based on dynamic slice reconstruction, belonging to the field of computer data security and file encryption technology. To address the problems of high memory consumption in existing whole-file encryption, insufficient obfuscation in sequential block encryption structures, incomplete file header recovery parameters, and weak enterprise authorization and decryption control capabilities, this invention obtains the file size, encryption level, and server key material of the file to be encrypted. It adaptively determines the block size based on the file size, generates a slice reconstruction seed based on the AES key, salt value, and file size, and uses this seed to construct a deterministic out-of-order block arrangement sequence. During encryption, a file header containing the key version, salt value, block size, number of blocks, original file size, slice reconstruction seed, and header checksum is generated. Each plaintext block is encrypted and authenticated using an independent initialization vector using AES-GCM, and then written to the ciphertext file in out-of-order order. During decryption, after server authorization is passed, the block arrangement sequence is reconstructed, and each block is authenticated, decrypted, and written back to its original logical offset position. This invention can improve the obfuscation capability of the physical structure of encrypted files while ensuring file recovery, reduce the memory footprint of large file encryption, and support key version management, authorized decryption, and automatic encryption based on enterprise policies.

Door lock networking communication method and system based on dynamic factor and identity binding

The invention discloses a door lock networking communication method and system based on dynamic factor and identity binding. The method comprises the following steps: an upper computer and door lock equipment read the same hotel authorization card to obtain the same hotel unique identifier ID; during communication, an upper computer generates a dynamic encryption key by using a timestamp of current communication, generates an initialization vector by using a hotel unique identifier ID, encrypts original data containing an anti-replay ID and functional data, and generates a plaintext frame header feature; after the door lock equipment receives the data packet, pre-checking the frame header features and checking the timeliness of the timestamps in sequence; and after the verification is passed, decrypting by using a locally stored hotel unique identifier ID as a vector, and carrying out ID replay prevention and integrity verification. According to the method and the device, the time is mapped into the secret key, the identity is mapped into the isolation vector, and the multi-stage verification funnel is matched, so that the problems of replay attack and multi-hotel signal crosstalk in a wireless environment are effectively solved, and the system security and the response efficiency are improved.
Owner:GLOBAL CARD SYSTEMS CO LTD

Industrial control system security auditing method and system

This invention relates to the field of security auditing technology, specifically to a method and system for security auditing industrial control systems (ICS). The method includes the following steps: collecting data on cycle time, start timestamp, completion timestamp, CPU time slice usage, and peak memory usage for critical control, communication, and security tasks of a real-time operating system (RTOS). This invention collects data on cycle time, timestamps, CPU usage, and memory usage of critical ROS tasks, sets task execution time boundaries and resource consumption envelopes, and then uses historical data statistics and logical rule deduction to construct a set of expected relationship rules between task timing and resource consumption. Simultaneously, it specifies the key length for symmetric and asymmetric encryption, initialization vector generation, hash algorithm selection, key derivation parameters, and encryption operation context, thereby establishing a comprehensive and specific baseline for ICS behavioral norms.
Owner:CHONGQING HUATAI ACCOUNTING FIRM (GENERAL PARTNERSHIP)

Dynamic library loading method and system, electronic device and storage medium

The application provides a dynamic library loading method and system, an electronic device and a storage medium. The method comprises the following steps: obtaining a target encrypted file, and obtaining a preconfigured decryption key and an initialization vector from a secure storage area; reading the content of the target encrypted file to a memory to obtain encrypted data; performing decryption processing on the encrypted data according to the decryption key and the initialization vector to obtain decrypted data; in the case that the decrypted data passes integrity verification, creating a memory anonymous file and writing the decrypted data into the memory anonymous file; loading the memory anonymous file through a dynamic loading interface to obtain a dynamic library handle; obtaining the address of a target in an original dynamic library file according to the dynamic library handle, and calling the address of the target to execute corresponding functions, and uninstalling the original dynamic library file through the dynamic library handle and safely clearing the decrypted data in the memory.
Owner:CHONGQING AEROSPACE POLYTECHNIC COLLEGE

Multi-counter memory encryption systems and techniques for targeted access of individual memory blocks

Disclosed aspects and implementations are directed to systems and techniques for multi-counter memory encryption with targeted access of individual memory blocks. In one example, replacing a stored block in a memory device includes encrypting a replacement block using a first initialization vector (IV) having a block counter associated with a number of times the stored block has been previously replaced, replacing the stored block with the encrypted replacement block in the memory device, encrypting a second IV to obtain a tag encryption vector, the second IV including a tag counter associated with a number of times an authentication tag for a plurality of blocks has been previously updated, and updating, using the encrypted second IV, the authentication tag for the plurality of blocks.
Owner:CRYPTOGRAPHY RESEARCH INC

Encryption method, device, storage medium and electronic device

ActiveCN116170180BAlgorithmCiphertext
The application discloses an encryption method and device, a storage medium and an electronic device. The method comprises the following steps: determining an original key, and obtaining an encryption key by iteratively processing the original key by a data encryption algorithm for a predetermined number of times; obtaining an initialization vector in a ciphertext structure, and obtaining an encrypted original ciphertext according to the encryption key and the initialization vector; obtaining an encryption salt, and splicing the encrypted original ciphertext, the initialization vector, the encryption salt and the predetermined number of times to obtain a target ciphertext. The application solves the technical problem that different encryption strength requirements cannot be implemented for different systems due to the difficulty in managing keys in the related art and the fixed encryption strength.
Owner:CHINA TELECOM CORP LTD

Methods for encrypting plaintext

The present invention relates to a method for encrypting (ENCR ZF ENCR1, ENCR2 M ) a plaintext (PT) which is part of a plaintext message Mp. The underlying idea of this method is to use a reversible decomposition function (ZF) that assigns two plaintext parts (PT1, PT2) to each plaintext (PT) to be encrypted. That is, ZF(PT) = (PT1, PT2) holds. Then, these plaintext parts (PT1, PT2) are encrypted by at least one encryption function (ENCR1, ENCR2) in two separate steps instead of one step, for example sequentially. Since the decomposition function (ZF) is reversible, for each plaintext to be encrypted, PT = ZF -1 (ZF(PT)) holds, where ZF 1 is the inverse function of the decomposition function. That is, using the inverse function (ZF -1 ), the original plaintext (PT) can always be uniquely derived from the plaintext parts (PT1, PT2). And this is used to decrypt the ciphertext message (M ZF ENCR1 , ENCR2 M ) containing the ciphertext parts (CT1, CT2) generated by the encryption (ENCR C ) through a corresponding decryption (DECR ZF DECR1, DECR2 M ). For this purpose, the ciphertext parts (CT1, CT2) are sequentially decrypted by at least one decryption function (DECR1, DECR2), and then the plaintext (PT) is retrieved therefrom. And instead of a conventional initialization vector for encryption and decryption, it is the selected bits, or all the bits, of the second plaintext part (PT2), or a bit sequence derived therefrom. Thereby, the message (M C ) to be transmitted can be shortened without sacrificing security.
Owner:MERCEDES BENZ GROUP AG