Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

641 results about "Key (cryptography)" patented technology

In cryptography, a key is a piece of information (a parameter) that determines the functional output of a cryptographic algorithm. For encryption algorithms, a key specifies the transformation of plaintext into ciphertext, and vice versa for decryption algorithms. Keys also specify transformations in other cryptographic algorithms, such as digital signature schemes and message authentication codes.

Quantum key distribution method based on cryptographic infrastructure system

The embodiment of the invention provides a quantum key distribution method based on a cryptographic infrastructure system, relates to the technical field of quantum secret communication, and provides a quantum key distribution method based on fusion of quantum key distribution and post quantum cryptography, which integrates a classical commercial cryptographic algorithm, a PQC post quantum cryptographic algorithm and quantum key distribution. A QKD-based quantum key secure distribution process combining SM2 and PQC mixed signature, SM2 and PQC mixed key packaging, PQC collaborative signature, PQC collaborative decryption, token access and other cryptographic technologies is designed, and anti-quantum cryptographic capability support is provided for voice applications through collaborative signature and collaborative decryption, so that the security of software for realizing a PQC cryptographic algorithm is improved, and the security of the PQC cryptographic algorithm is improved. Moreover, the software implementation mode does not have the inherent security problem of the IP, the dependency on the server is low, and the standardization program is high.
Owner:中电信量子信息科技集团有限公司

SSL VPN security gateway communication method fused with post quantum cryptography

The invention discloses an SSL VPN security gateway communication method fused with a post quantum cryptography technology. Comprising the following steps: S1, a client and a server respectively configure a serial hybrid signature digital certificate containing an SM2 algorithm and a serial hybrid encryption digital certificate containing a PQC algorithm, and a corresponding PQC encryption key pair private key, a PQC signature key pair private key, an SM2 encryption key pair private key and an SM2 signature key pair private key; s2, newly adding a hybrid algorithm password suite using an SM2 algorithm and a PQC algorithm in a password suite list of the client, and forcibly jacking the priority of the hybrid algorithm password suite; and S3, a message structure in a handshake protocol is transformed to use a series hybrid encrypted digital certificate to realize that PQC algorithm processing is added on the basis of an original national cryptographic algorithm to realize quantum key negotiation resistance. According to the method, the PQC algorithm is added on the basis of the original national secret algorithm, and the handshake protocol is transformed, so that anti-quantum-attack key agreement and identity authentication can be realized, the communication security is remarkably improved, and meanwhile, the interoperability with the standard SSL VPN is kept.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Education robot-based intelligent system and method for fusing mental health evaluation in interest scene

PendingCN120636769AEnsemble learningDigital data protectionNumber generatorPsychometric testing
The invention discloses an intelligent system and method for fusing mental health evaluation in an interest scene based on an education robot. The system realizes non-intrusive mental health assessment by constructing a technical architecture of'multi-modal biological feature anonymization-quantum hybrid encryption-federated learning privacy protection-dynamic risk assessment '. The method is characterized by comprising the following steps of: (1) generating irreversible biological characteristic codes by adopting a chaos random number generator, and realizing anonymized association by combining a double hash chain technology; (2) designing a quantum enhanced hybrid encryption system, fusing an SM4 algorithm, NTRU post quantum cryptography and quantum key distribution; (3) developing a dynamic scene generator, and naturally fusing psychological test questions into interest topics by using a generative adversarial network (GAN) and a curiosity engine; (4) constructing a multi-modal emotion analysis system, and combining an LSTM + CNN hybrid model to realize physiology-behavior-voice data fusion analysis; and (5) deploying a federated learning framework, and protecting model training data through differential privacy noise injection (epsilon = 0.5).
Owner:张景飞

Configurable number-theory transformation parallel computing acceleration method and device for post quantum cryptography algorithm

The invention discloses a configurable number-theory transformation parallel computing acceleration method and device for a post quantum cryptographic algorithm, and relates to the technical field of cryptographic algorithms. The number theory transformation is a calculation bottleneck in lattice-based post-quantum cryptography and PQC; a hardware accelerator specially designed for number theory transformation (NTT) is an effective solution for improving the execution speed. At present, a mainstream design neglects the influence of the scale of a calculation array, so that the design of an NTT calculation circuit is poor in flexibility and low in memory utilization rate, and a two-dimensional reconfigurable number theory transformation acceleration circuit is provided; the method is applied to a key generation stage, an encryption stage and a decryption stage of the post-quantum cryptographic algorithm. The NTT reconfigurable computing circuit provided by the invention can keep the utilization rate of hardware resources, and is suitable for mobile terminal equipment with limited resources; the NTT circuit adopts a low-complexity memory mapping scheme, so that the address control logic is greatly simplified, and the hardware overhead is reduced.
Owner:BEIJING INST OF TECH +1

Vehicle-gauge-level rear quantum cryptography acceleration and side channel protection device

The invention relates to the technical field of vehicle-gauge-level password protection, and discloses a vehicle-gauge-level post quantum password acceleration and side channel protection device. The device comprises a quantum key injection unit, a quantum noise analysis unit, a post quantum cryptography acceleration engine, a side channel feature extraction unit and a protection strategy generator. The quantum key injection unit performs format standardization processing on input quantum key information; the quantum noise analysis unit collects a power consumption time sequence signal and an electromagnetic radiation signal of the cryptographic operation chip, and extracts a quantum noise characteristic spectrum through a quantum Fourier transform algorithm; the post quantum cryptographic acceleration engine adopts a lattice-based cryptographic algorithm to implement layered acceleration operation on the target encrypted message data; a side channel feature extraction unit constructs a space-time joint side channel feature tensor according to the quantum noise feature spectrum; the protection strategy generator identifies the physical fragile area according to the tensor and generates a corresponding protection strategy instruction. The device integrates a quantum cryptography acceleration function and a side channel protection function, and is suitable for a vehicle-specification-level scene.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Dynamic key generation system and method based on multi-source QRNG and QKD

The invention relates to the technical field of quantum cryptography, in particular to a dynamic key generation system and method based on multi-source QRNG and QKD, and the system comprises an interface registration method, a calling method, related equipment and a storage medium, is used for generating a high-security quantum key, and is a quantum key service system with a layered architecture. By abstracting, integrating and managing bottom-layer multi-source QRNG and QKD equipment and fully utilizing the flexible scheduling of quantum equipment, the security of key generation is ensured, so that the key service has higher performance, usability and security, and unified, dynamic and high-security quantum key generation and supply services are provided for various applications of the upper layer. The method is widely applied to the industries and fields of government, finance, energy, traffic, electric power and the like, meets the requirements of quantum key acquisition of various business applications in cloud computing and non-cloud environments, and ensures information security and business continuity.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUIZHOU) CO LTD

Data verification method and device based on two-dimensional code third-party login and national secret authentication

The invention provides a data verification method based on two-dimensional code third-party login and national secret authentication, and the method comprises the steps: obtaining a user identity bill and obtaining a private key password corresponding to the user identity bill by an encryption end when a login request sent by a user end through scanning a login two-dimensional code of a login end is received; the encryption end encrypts the private key password to obtain an encrypted key password, and sends the encrypted key password to the login end; the encryption end determines collaborative signature response data according to the collaborative signature request and the user identity bill and sends the collaborative signature response data to the login end; and the encryption end verifies the complete signature through the verification request, and sends a verification result to the authentication end. By arranging the encryption end, national secret authentication and two-dimensional code third-party login are combined, and the safety of logging in a third-party website when the two-dimensional code is scanned is guaranteed.
Owner:SHENZHEN OLYM INFORMATION SECURITY TECHOLOGY CO LTD

Secure Communication for Connected Systems Using Post Quantum Cryptography

Embodiments of the present disclosure provide techniques for providing secure communication for connected systems. The techniques may include receiving a communication session indication associated with a first connected system; authenticating the first connected system based on IAM policy; encrypting a message to generate an encrypted message based on a post quantum cryptography public key associated with the first connected system; and causing transmitting of the encrypted message to a second connected system.
Owner:HONEYWELL INTERNATIONAL INC

Key sharing and detection scheme based on intelligent electric meter

The invention discloses a key sharing and security detection scheme based on an intelligent electric meter, and aims to solve the problems that an untrusted electric meter in an intelligent power grid is difficult to identify effectively, the detection scale is uncontrollable and the communication security is insufficient. According to the scheme, the elliptic curve cryptography, the threshold secret sharing mechanism and the physical unclonable function are combined, and hardware-level binding of the unique identity of the equipment and the secret key is achieved in the registration stage. Through a threshold password mechanism, a plurality of intelligent electric meters cooperatively participate in key reconstruction and encryption communication, and the intelligent electric meters can still work normally when part of the electric meters fail or are broken through. The center node can actively identify a fault or a malicious ammeter and dynamically adjust a communication strategy according to the integrity and correctness of the feedback information. Meanwhile, the scheme supports dynamic identity updating and integrity verification, and effectively resists modeling attacks, Sybil attacks, replay attacks and DoS / DDoS attacks. According to the invention, secure identity authentication, reliable key distribution and efficient anomaly detection are realized, and the security of smart grid terminal communication is improved.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Federal learning model property right protection method based on quantum coding and lattice password

The invention relates to the technical field of artificial intelligence, in particular to a federated learning model property protection method based on quantum coding and lattice passwords. The method comprises the steps that firstly, an initial global model is distributed, and quantum watermark generation and embedding are carried out on the basis of the initial global model in combination with lattice password quantum state coding and an information theory; then, generating corresponding quantum fingerprints based on the initial global model embedded with the watermark, aggregating the quantum fingerprints by adopting a multi-key homomorphic encryption method to obtain global aggregated fingerprints, and recording corresponding identity information in a DAG account book; and finally, receiving verification information, and performing model ownership affiliation verification based on the verification information and the identity information in combination with a zero-knowledge proof protocol based on a lattice difficulty problem. The watermark is encrypted by an LWE instance, and any calculation behavior trying to remove the watermark is equivalent to solving a difficult LWE problem, which is not feasible in calculation. Excellent performance is achieved by adopting an advanced lattice cryptographic algorithm.
Owner:SOUTHWEST JIAOTONG UNIV

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Computer implemented method and system for knowledge proof in blockchain transactions

A method of enabling knowledge proof in a blockchain transaction is disclosed. The method comprises sending, from a verifier to a prover, a blockchain transaction redeemable by means of data including (i) first data (y) based on a combination of an ephemeral key (r), second data (c) and a private key of a public-private key pair of a cryptography system, wherein the public key (v) is based on an integer generator raised to a first power, wherein the first power is based on the private key, and wherein knowledge of the private key is required in order to determine the ephemeral key from the first data, and (ii) third data (x) based on the integer generator raised to a second power, wherein the second power is based on the ephemeral key.
Owner:NCHAIN LICENSING AG

Data access control method and system based on zero knowledge proof

The invention provides a data access control method and system based on zero-knowledge proof, and relates to the technical field of data access control. According to the method, a root key of a unique hardware identity is generated through a physical unclonable function of a data request equipment chip, and meanwhile, real-time running state data of equipment is collected; the two are subjected to cryptographic binding to form an equipment credible state voucher; secondly, detecting capacitance field disturbance when data holding equipment approaches through a capacitive proximity sensor array, and generating an interactive response mode; then, the equipment credible state certificate and the interactive response mode serve as private input to generate a composite zero-knowledge proof, and identity authenticity and physical proximity are proved to data holding equipment at the same time on the premise that sensitive information is not leaked; and after the data holding device passes verification, the data access permission is authorized immediately, and a temporary encryption communication channel is established, so that the reliability and instantaneity of security authentication between IoT devices can be improved.
Owner:NANJING YISHENG SAFETY TECH RES INST CO LTD +1

Quantum cipher migration resisting method and system, electronic equipment and storage medium

The invention relates to an anti-quantum password migration method and system, electronic equipment and a storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: carrying out adaptive expansion on a transport layer security protocol; the encryption end and the decryption end perform secure transmission of the application data based on the expanded transport layer security protocol, and the secure transmission process of the application data comprises the following steps: generating a master key, a multi-level sub-key and a path key chain according to a chain type post-quantum key generation mechanism based on the expanded cipher suite; the encryption end generates an encryption key through a part of the sub-keys, encrypts application data in a symmetric encryption mode to generate a ciphertext, and sends the ciphertext and a path node key at the tail end of the path key chain to a decryption end; and the decryption end verifies the path node key, generates a decryption key by using part of the sub-keys after the verification of the path node key is passed, and decrypts the ciphertext. According to the invention, the security and high efficiency of data transmission in the anti-quantum cryptography migration process are realized.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Remote signature system and tamper resistant device

The present invention realizes a remote signature system in which identity verification is performed for each signing request by combining the remote signature system with public key cryptography. A terminal device (2) comprises a means for generating a key pair for authentication to perform the public key cryptography. A generated secret key is stored in the terminal device (2), and a generated public key is transmitted to the tamper resistant device (5) and is stored in relation with the corresponding signature key. The tamper resistant device comprises a signature key storage means (12) for storing the signature key, a decryption key and signature key identification information as pairs for each user. When requesting a digital signing, a signing request including the signature key identification information, plaintext verification information, and a crypto token including the encrypted verification information and the encrypted signature object data is created and is transmitted to the tamper resistant device (5). The tamper resistant device accesses to the signature key storage means (12) and searches both the decryption key and the signature key. The tamper resistant device decrypts the crypto token using the searched decryption key, and verifies consistency between the decrypted verification information and the plaintext verification information. If they do not match each other, the signing request is excluded from the digital signing.
Owner:KEY TECHNO CO LTD

IPSec VPN security gateway communication method based on post quantum cryptography

The invention discloses an IPSec VPN security gateway communication method based on a post quantum cryptography technology, and the method comprises the following steps: S1, replacing a conventional SM2 algorithm and a certificate with a PQC algorithm and a digital certificate in a first-stage main mode of IKE key negotiation; s2, the initiator and the responder respectively use the PQC key pair to complete key exchange and signature; s3, in the message 1, the initiator sends a security alliance load containing a PQC public key algorithm attribute to the responder; s4, in the message 2, the responder sends an SA load containing a PQC signature certificate and an encryption certificate, and a received SA proposal sent by the initiator is marked; s5, in the message 3 and the message 4, the initiator and the responder complete key exchange and verification; and S6, in the message 5 and the message 6, the initiator and the responder encrypt the transmitted information by using a symmetric cryptographic algorithm, and identify the previous exchange process. According to the invention, the security of the IPSec VPN security gateway is improved, and quantum computing attacks can be resisted.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Computer-implemented system and method for managing authentication between user device and authentication server using private-public key cryptography

A computer-implemented method and system for managing an authentication between user devices and authentication servers, is disclosed. The computer-implemented method includes: obtaining user credentials associated with users; retrieving information associated with device fingerprints corresponding to the user devices; generating cipher messages by at least one of: creating random numbers and encrypting the random numbers with keys derived from at least one of: the first and second index; transmitting the one or more user identities, the first index, the second index, and the cipher messages, to authentication servers; dynamically generating the private keys from private key variables; generating authentication responses by decoding authentication based questions obtained from the authentication servers, using cipher messages and the private keys; and transmitting the authentication responses to the authentication servers for adapting the authentication servers to authenticate the user devices.
Owner:HAWCX INC

Configurable module-lattice post-quantum cryptography processor for key-encapsulation mechanism

Disclosed is a reconfigurable module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system and method using memory-based numbers theoretic transform (NTT). A post-quantum cryptography method of a post-quantum cryptography system including a plurality of internal submodules includes reconfiguring the plurality of internal submodules by variably selecting one security level from among the plurality of security levels; reconfiguring execution of the plurality of internal submodules to be changed through a main controller; and variably processing data according to the selected security level to perform key generation, encapsulation, and decapsulation through the reconfigured plurality of internal submodules.
Owner:INHA UNIV RES & BUSINESS FOUNDATION

File encryption method and device based on quantum cryptography resisting technology

The invention discloses a file encryption method and device based on an anti-quantum cryptography technology, and the method comprises the steps: selecting a target encryption algorithm and a target signature algorithm from a preset anti-quantum cryptography algorithm library in response to a file encryption instruction; generating an asymmetric key pair corresponding to the target encryption algorithm through a secure random number generator; the asymmetric key pair comprises a target public key and a target private key, and the target private key is stored in the protected area; dividing a to-be-encrypted original data file into a plurality of file data blocks; using the target encryption algorithm and the target public key to perform hybrid encryption processing on the file data blocks in sequence to generate encrypted data blocks; performing signature processing on the encrypted data block by using a target signature algorithm to generate a digital signature corresponding to the encrypted data block; and performing data packaging on the encrypted data block and the digital signature to determine an anti-quantum encryption file corresponding to the original data file. And the encryption efficiency is considered while the file resists the quantum computing attack.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

Two-factor authentication key negotiation method and system based on biological characteristics

The invention relates to the field of cryptology, and discloses a two-factor authentication key negotiation method based on biological characteristics, a user holds double authentication factors, namely a private key authentication factor and a biological characteristic authentication factor, a server holds secret information, and the private key authentication factor and the biological characteristic authentication factor perform mutual authentication and form a shared key, so that the service can be obtained. A user can pass authentication only by holding two authentication factors at the same time, and when an enemy steals one authentication factor or secret information of a server, the enemy cannot disguise that the user passes the authentication of the server; even if an enemy steals the two authentication factors of the user, the enemy cannot be disguised as a server to pass the authentication of the user, so that the authentication threshold is greatly improved, an unauthorized user / server is prevented from abusing the authority of the authorized user, the security is higher, the entropy rate of a biological source is not required, and the authentication efficiency is higher.
Owner:SHANGHAI JIAOTONG UNIV

Centralized quantum key relay network and key distribution method

The invention provides a centralized quantum key relay network and a key distribution method, relates to the technical field of quantum communication, and comprises four steps of relay request initiation and demand analysis, path constraint and decision, cooperative key generation and verification, and monitoring and processing in a transmission process. Through the quantum digital signature, the quantum security MAC check code and the post quantum cryptography signature mechanism, the security of the system facing the quantum computing threat is greatly improved, and meanwhile, the dynamic path selection combining the aging level, the multi-factor dynamic scoring model and the elastic target time window is adopted; according to the method, the optimal path and the target time can be dynamically adjusted according to the timeliness requirement, the path condition and the network state of the request, the path selection is more flexible, different timeliness requirements are met, the integrity and legality of the secret key are ensured by adopting a three-level verification mode, and meanwhile, when the network has a fault, the safety of the network is ensured. A standby path can be automatically switched and a problem node can be isolated.
Owner:ANHUI POLYTECHNIC UNIV +1

Power protection measurement and control terminal information security protection method, system, equipment and medium

The invention discloses an electric power protection measurement and control terminal information security protection method, system and device and a medium, and the method comprises the steps: building an environment fingerprint database through collecting the physical quantity of a power grid, carrying out the threat level evaluation, and adjusting a security strategy; based on the environment fingerprint database and the threat level evaluation result, classifying the transmission data, deploying quantum key distribution nodes in the transformer substation, and providing differentiated secure transmission for different types of transmission data; and in combination with the environment fingerprint database and the differentiated secure transmission data, executing cognitive security analysis, establishing an anomaly detection model, and obtaining threat traceability visual positioning. According to the method, the dynamic environment fingerprint database is constructed by collecting multi-dimensional physical quantities and is bound with the digital certificate to form a dual authentication mechanism, so that the defect that a traditional scheme depends on static cryptography is overcome, real-time perception and adaptive response to a complex and changeable electromagnetic environment are realized, and the security of the system is improved. And the environmental adaptability and the safety protection capability of the system are obviously improved.
Owner:GUIZHOU POWER GRID CO LTD

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

System and method for scalable stream encryption and decryption

Information security systems and methods are presented including synchronized state machines operating with private data and tamper-evident identifiers that expand the problem space of attacks by unauthorized consumers of data in flight or rest to near infinity. A quantum cryptography-resistant distribution network for identity, trust relationship, encryption, and transcoding of valuable information is described where a priori knowledge of the hardware or software is irrelevant to the safe time for the data protected and modified as needed within a multikey encryption and data control and availability assurance domains. Due to its low compute design, the methods described within are well suited for a variety of tasks including real-time data streams such as video and audio distribution.
Owner:NEURSCIENCES LLC

Decentralized virtual identity key collaborative management system based on block chain

The invention discloses a decentralized virtual identity key collaborative management system based on a block chain, and belongs to the field of block chain technology and cryptography. The system comprises a block chain network layer used for distributed storage of key fragments and execution of an automation strategy; the virtual identity management module is used for generating a unique identity identifier (DID) through a threshold signature algorithm after fusing the biological characteristics and the device fingerprints; the key collaborative management module is used for storing the main key in a fragmented manner through a Shamir secret sharing algorithm, and dynamically selecting an encryption algorithm to generate a sub-key according to the security score of the target platform; the verification and auditing module is used for verifying the holding legality of the secret key through a zk-SNARKs technology and injecting random noise to resist side channel attacks; and the block chain network layer, the virtual identity management module, the key collaborative management module and the verification and auditing module are connected with an encrypted communication protocol through an intelligent contract interface.
Owner:HENAN INFORMATIZATION GRP CO LTD

Key distribution method and device for quantum security infrastructure, equipment and medium

The invention provides a key distribution method, device and equipment for quantum security infrastructure and a medium, and relates to the technical field of quantum secure communication and post quantum cryptography, the method comprises the following steps: in a key distribution process, confirming the credibility of a mobile terminal through a first new person strategy, and using a temporary encryption public key to securely transmit a key pair, the security of key transmission is improved, the flexibility is improved through automatic certificate online signing and issuing of an agent, and the password book can be securely transmitted through the use of the certificate and the key pair and the construction of a secure transmission channel, so that the terminal of the quantum security infrastructure can obtain the corresponding core key key elements based on an online mode, and the security of the key transmission is improved. The application expansibility of the quantum security infrastructure is greatly improved, and the security strength of the system is guaranteed.
Owner:中电信量子信息科技集团有限公司

Network security monitoring method and system based on Internet of Things

The invention discloses a network security monitoring method and system based on the Internet of Things, and relates to the technical field of Internet of Things security. Through dynamic challenge-response physical unclonable authentication, physical parameters and a real-time state are fused to generate a dynamic challenge value, and a physical unclonable function circuit is combined to generate a response value to realize identity verification; adaptive noise lattice-based homomorphic encryption is adopted, a ciphertext is generated based on a high-dimensional lattice-based password, and noise parameters are adjusted through channel quality to guarantee transmission security; multi-modal confrontation federated learning anomaly detection is utilized, flow, energy consumption and physical state characteristics are fused, and parameters are aggregated through a confrontation auto-encoder training model and based on federated learning; through dynamic threshold key negotiation, in combination with identity-based encryption and a block chain smart contract, distributed generation and dynamic adjustment of a key are realized; on the basis of a Merkle-salt value dynamic hash chain and block chain evidence storage, a log is generated in a trusted execution environment, a hash chain is constructed, and chain tail hash is synchronized to block chain evidence storage.
Owner:JIAYUGUAN JINNUOYI SUPPLY CHAIN CO LTD

Hybrid encryption method and device and storage medium

The invention provides a hybrid encryption method and device and a storage medium, and the method comprises the steps: a client generates a short-term SM2 key pair and exchanges with a server after obtaining a long-term SM2 key pair and a server public key, dynamically generates a session SM4 symmetric key through an SM2 key exchange protocol, and finally achieves the data transmission and response processing through the session SM4 symmetric key. Through the implementation of the scheme of the invention, the client not only establishes the basic trust relationship based on the long-term SM2 key pair, but also generates the short-term SM2 key pair during each service request, and dynamically derives a unique session SM4 symmetric key and an initial vector by cooperatively executing the SM2 key exchange protocol with the short-term key of the server. And each request has an independent security context, so that the decryption risk after the session key is reused or stolen is fundamentally prevented, and the end-to-end dynamic security communication under the national secret system is really realized.
Owner:SHANGHAI FEIWEI INFORMATION TECH CO LTD +2