Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

388 results about "Key (cryptography)" patented technology

In cryptography, a key is a piece of information (a parameter) that determines the functional output of a cryptographic algorithm. For encryption algorithms, a key specifies the transformation of plaintext into ciphertext, and vice versa for decryption algorithms. Keys also specify transformations in other cryptographic algorithms, such as digital signature schemes and message authentication codes.

Dynamic key generation system and method based on multi-source QRNG and QKD

The invention relates to the technical field of quantum cryptography, in particular to a dynamic key generation system and method based on multi-source QRNG and QKD, and the system comprises an interface registration method, a calling method, related equipment and a storage medium, is used for generating a high-security quantum key, and is a quantum key service system with a layered architecture. By abstracting, integrating and managing bottom-layer multi-source QRNG and QKD equipment and fully utilizing the flexible scheduling of quantum equipment, the security of key generation is ensured, so that the key service has higher performance, usability and security, and unified, dynamic and high-security quantum key generation and supply services are provided for various applications of the upper layer. The method is widely applied to the industries and fields of government, finance, energy, traffic, electric power and the like, meets the requirements of quantum key acquisition of various business applications in cloud computing and non-cloud environments, and ensures information security and business continuity.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUIZHOU) CO LTD

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

Data security protection method, device and system based on anti-quantum cryptography algorithm

The invention provides a data security protection method, device and system based on an anti-quantum cryptography algorithm, and the method comprises the steps: setting a security storage agent node, enabling the security storage agent node to divide original data into hot data or cold data according to the security level of the original data and access data, the hot data and the cold data are encrypted by adopting different encryption modes, so that the data processing performance is optimized under the condition of ensuring the data security; besides, the data encryption key is subjected to fragmentation encryption, a separated secure storage mode is adopted, the traditional key trusteeship single-point risk is broken through, the data security is further improved, the data encryption key is subjected to fragmentation encryption by adopting a post-quantum encryption algorithm, quantum attack can be effectively resisted, and long-term data security can be guaranteed.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Security key generation and authentication method based on microfluidic DNA detection

The invention discloses a micro-fluidic DNA detection-based security key generation and authentication method, which comprises the following steps: S1, carrying out DNA detection on a biological sample through a micro-fluidic chip to obtain SNP and STR feature data; s2, performing unified coding on the SNP and STR feature data to form stable bit string representation; s3, processing the bit string representation by using a fuzzy extraction mechanism, and generating a consistent key material under the condition of permitting a detection error; s4, deriving a final symmetric key from the key material by using a key derivation function; and S5, performing security packaging, transmission and authentication on the final symmetric key by adopting a post-quantum cryptography mechanism. According to the security key generation and authentication method based on microfluidic DNA detection, a set of key generation and identity authentication scheme with instantaneity, high specificity and anti-quantum security is constructed.
Owner:GUANGDONG UNIV OF TECH

Efficient multi-authority responsibility investigation multi-party authorization method and device based on attribute encryption

The invention discloses a high-efficiency multi-authority responsibility investigation multi-party authorization method and device based on attribute encryption, and belongs to the technical field of cryptography and information security. A multi-authority attribute-based encryption mechanism is adopted to protect a responsibility investigation private key, a signer encrypts a signature share and generates a zero-knowledge proof; after verification and certification of the combiner, an encrypted share is aggregated in a ciphertext domain to generate an aggregated ciphertext, the block chain stores a hash abstract, and an authorization tracker decrypts the aggregated ciphertext through an attribute key recovery responsibility investigation private key to recover a threshold signature and a participant set, so that cryptology privacy protection, constant-level responsibility investigation efficiency, decentralized governance and reliable auditing are realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Lightweight hierarchical trust access authentication method and system based on identification

The invention discloses an identification-based lightweight hierarchical trust access authentication method and system, and mainly relates to the technical field of network security. Comprising the following steps: in an offline stage, an electric power registration center generates a private key root bound with an identity for a terminal through identity-based cryptography, a key generation center derives a lightweight work key voucher and pre-calculates verification points of all terminals, and a unified main multi-dimensional Bloom filter is constructed and distributed to a main station; in the online stage, a terminal updates a key and generates a signature only through hash operation, a master station reconstructs candidate verification points after receiving a message, and non-interactive verification is completed by locally querying a master multi-dimensional bloom filter. The method has the advantages that unification of strong identity credibility and extreme light weight of the terminal is achieved, the terminal side only needs efficient Hash operation, the server supports high-concurrency and low-delay authentication through the pre-calculation and Bloom filter technology, and the problem of safe access of massive distributed terminals in the electric power Internet of Things is effectively solved.
Owner:STATE GRID SHANDONG ELECTRIC POWER COMPANY WEIFANG POWER SUPPLY +1

A blockchain-based method for communicating application sensitive data

The application relates to the technical field of blockchains, and particularly discloses an application sensitive data communication method based on a blockchain, which comprises identity registration and trusted booting, strategy on-chain and commitment, session negotiation and encryption encapsulation, controlled unsealing and verifiable calculation, on-chain verification and auditing, and revocation and emergency. The scheme realizes minimum exposure of application sensitive data through the blockchain technology; the visible range of data is controlled through verifiable access strategies and short-term session keys; key operations are fixed in the blockchain through threshold cryptography and trusted execution environments, so that the operations are verifiable; on-chain and off-chain cooperation and batch processing aggregation are adopted, so that the communication and calculation burdens are reduced.
Owner:MIANYANG TEACHERS COLLEGE

Method and apparatus for protecting cryptographic keys in the process of migration to post-quantum cryptography

A method and apparatus for securing a device to operate in a post quantum computing environment is disclosed. In one embodiment, the method comprises a first stage of performing a secure boot of the processor, using the pre-provisioned, protected symmetric boot key, a second stage of generating, by the processor, at least one post quantum cryptography (PQC) key pair having a PQC private key and a PQC public key; encrypting the PQC private key according to the pre-provisioned protected symmetric key, storing the encrypted PQC private key in the secure memory, generating a request having the PQC public key; and transmitting the request to an agency external to the processor. A third stage of deploying PQC safe applications is also disclosed.
Owner:ARRIS ENTERPRISES LLC

Cloud distributed node identity authentication method based on identity identification certificate

The invention discloses a cloud distributed node identity authentication method based on an identity label certificate, and aims to solve the problems of single-point failure, difficulty in cross-domain mutual recognition, efficiency and privacy imbalance and the like of a traditional authentication scheme. The system is composed of an identity identification certificate generator, a distributed certificate verification network and a block chain certificate account book, a master key is split through threshold secret sharing, the overhead is optimized through BLS signature aggregation, state consistency is guaranteed in combination with DHT and gossip protocols, and certificate full-life-cycle management is achieved through block chain certificate storage and an intelligent contract. The process includes system initialization, identity registration and certificate issuing, identity authentication and certificate updating and revocation, technologies such as elliptic curve cryptography and zero-knowledge proof are adopted, and security, efficiency and privacy protection are considered. The method is suitable for multiple scenes such as a power grid and the Internet of Things, supports cross-domain mutual recognition and dynamic capacity expansion, can effectively prevent illegal access and data tampering, and is suitable for large-scale cloud distributed node identity authentication.
Owner:GUANGXI POWER GRID CORP

Anti-quantum method and system based on stateless signature and execution isomorphism

This invention discloses a quantum-resistant method and system based on stateless signatures and execution isomorphism, belonging to the field of quantum-resistant cryptography. First, the sender generates an mKEM broadcast payload based on a modulus error rounding algorithm and signs it using a stateless hash signature algorithm. The receiver performs microsecond-level verification of the signature at the network card driver layer; if verification fails, the signature is silently discarded. After successful verification, a dedicated PQC hardware engine decapsulates the signature, implicitly outputting a pseudo-random scrap key if verification fails. The operating system executes an I / O-aware microarchitecture with isomorphic execution, forcing subsequent processes to maintain physical isomorphism in system calls, memory accesses, and peripheral bus activities, regardless of whether the key is real or scrap. This invention eliminates the risk of private key leakage caused by cloud-based state management through stateless signatures and completely eliminates distinguishable side-channel fingerprints across the entire link through physical-level execution isomorphism, achieving system-level quantum-resistant security in high-concurrency scenarios.
Owner:BEIJING LANGKONG QUANTUM TECHNOLOGY CO LTD

Power equipment identity fingerprint generation method, verification method and device

The invention discloses a power equipment identity fingerprint generation method, verification method and device, and the method comprises the steps: obtaining the software and hardware static identity information and dynamic identity information of power equipment; wherein the dynamic identity information is obtained according to the private data of the power equipment, or a public key and a private key are generated by using a cryptographic key generation method, and the public key is used as the dynamic identity information; performing Hash calculation according to the identity information to obtain the identity information of the power equipment; and converting the identity information of the power equipment into a form conforming to a specified format, namely the identity fingerprint of the power equipment. According to the invention, identity fingerprints based on the combination of software and hardware static information and cryptography dynamic information are provided for power equipment, and identity verification and living body detection of a verification party on the equipment are completed in one message interaction based on a non-interactive zero-knowledge proof method; and the potential safety hazard that the identity fingerprint of the power equipment is easily counterfeited and illegally abused is solved.
Owner:NR ELECTRIC CO LTD +2

An outsourcing encrypted database system and method based on a TEE server supporting a secure aggregation operation and a secure query operation

The application discloses an outsourcing encrypted database system and method based on a TEE server supporting a secure aggregation operation and a secure query operation. The system comprises a client and a cloud server configured with a rich execution environment (REE) and a trusted execution environment (TEE). The client generates a key pair, and adopts a Paillier threshold encryption strategy to split the private key into two shards, which are respectively sent to the REE and the TEE, and the data encrypted by the public key is stored in the REE. When responding to a query or aggregation instruction, the REE and the TEE cooperatively execute a cryptography operation protocol by using the private key shards held by each other through a hardware isolation mechanism. In order to further improve the processing efficiency, the application also introduces amortization optimization technology, which uses the property of homomorphic encryption to package multiple independent comparison tasks into a ciphertext for one-time joint decryption, thereby significantly reducing the calculation overhead and communication bandwidth.
Owner:GUANGZHOU RES INST OF XIAN UNIV OF ELECTRONIC SCI & TECH

Multimodal memory integrated circuit with native-speed encrypted data processing for use in unbreakable cryptography

A method of native-speed encrypted data processing for use in cryptography includes the following steps: receiving, from a memory on a chip substrate of a multimodal integrated circuit (IC) chip, a first set of data encrypted by a first OTP key; receiving, from the memory, at least a second set of data encrypted by at least a second OTP key; decrypting the first set of data; processing, by a first externally-originating operation on the at least one processing device, the decrypted first set of data; encrypting the processed first set of data; decrypting the at least second set of data; processing, by at least a second externally-originating operation on the at least one processing device, the decrypted at least second set of data; and encrypting the processed at least second set of data.
Owner:QUANTUM PROPERTIES TECHNOLOGY LLC

Quantum-resistant encryption method and system for core data of power system based on lattice cryptography

The application provides a power system core data quantum-resistant encryption method and system based on lattice cryptography, relates to the technical field of power system information security, and comprises the following steps: decomposing core data into orthogonal subspace components, constructing a quantum-resistant key pair based on a lattice difficult problem, performing state migration through multiple rounds of lattice basis transformation and noise injection, and finally assembling a ciphertext-related hash chain. The application can resist quantum computing attacks, improve the security of power system core data, realize efficient encryption processing, and guarantee the structural integrity and traceability of data.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Key pair generation

A method for generating a private key for an asymmetric key cryptography algorithm using a password, wherein the password can be changed without the private key changing is presented. The method has applications to blockchain wallets, digital signing, passkeys, and other identity and access management systems in which password changing is currently difficult or impossible. The method generates a first matching code for a first password to derive a private key, and when the first password is changed to be a second password, the first matching code is altered to a second matching code to maintain derivation of the same private key, and the first password may be discarded or forgotten.
Owner:CHEQS GLOBAL LTD

Key cooperative exchange method and device, electronic equipment and medium

This application discloses a method, apparatus, electronic device, and medium for collaborative key exchange. In this application, upon receiving a peer random number public key from a peer key device, the peer random number public key and a first random number public key are sent to a second communicating party. The first random number public key is calculated by the first communicating party using an elliptic curve cryptography algorithm. The second communicating party calculates its own random number public key based on the peer random number public key, the first random number public key, and a second sub-private key, and then sends its own random number public key and intermediate parameters to the first communicating party. The first communicating party calculates a shared key based on its own random number public key, intermediate parameters, and the first sub-private key, and then sends its own random number public key to the peer key device.
Owner:BEIJING WATCH DATA SYSTEM CO LTD

Remote key security management method and device for cloud virtualization cryptographic module

The invention discloses a remote key security management method and device for a cloud virtualization cryptographic module, and aims to solve the problems of cloud key trust root, transmission security and the like. The core of the method is to keep the master key control right of a user locally, and through cooperative work of a local client, a cloud management platform and a distributed vHSM instance, through the four steps of system initialization and key fragmentation distribution, remote certification and secure channel establishment, distributed cooperative operation and local result synthesis, and by utilizing IBE, Shamir secret sharing, a threshold cryptographic algorithm and TEE technologies, the user master key control right and the distributed vHSM instance are subjected to remote certification and secure channel establishment, distributed cooperative operation and local result synthesis. And the key is available and invisible. The device comprises three modules, namely a local client, a cloud management platform and a vHSM cluster. The method guarantees secret key confidentiality and completeness, supports a national secret algorithm, meets compliance requirements, adapts to cloud native elasticity requirements, and is suitable for cloud secret key management in industries such as electric power and the like.
Owner:GUANGXI POWER GRID CORP

MPC threshold signature method and system suitable for HSM

The invention discloses an MPC threshold signature method and system suitable for HSM, and relates to the technical field of information security and cryptography, and the method comprises the steps: a management module manages a plurality of hardware security modules HSM, coordinates a key generation module of each HSM to execute a distributed key generation protocol DKG, and enables a private key fragment to be directly generated in each HSM and to be encrypted and stored; the MPC threshold signature module receives a to-be-signed message of an application APP and user certificate information, calls the management module to perform identity verification on the user certificate information, and obtains a target HSM node list associated with a user passing verification; the MPC threshold signature module schedules a threshold signature module with at least a threshold value of t HSM nodes according to the target HSM node list, and MPC threshold signature operation is executed in each HSM based on private key fragments; and the MPC threshold signature module receives partial signatures returned by each HSM, and aggregates the partial signatures into a standard digital signature for realizing efficient, compliant and single-point fault resistant digital signature operation on the premise of ensuring absolute security of the private key.
Owner:山东三未信安信息科技有限公司 +1

Merkle tree integrity protection for stateful hash-based cryptography

A method for verifying the integrity of a binary tree graph structure having "h" layers and a plurality of nodes configured to provide public keys, the method comprising: verifying the integrity of a stored root hash value associated with a root node; obtaining non-root nodes among the plurality of nodes, the "h" layers including leaf layers, and the leaf layers including a plurality of leaf nodes associated with a plurality of one-time signature public keys; obtaining an authentication path associated with the non-root node, the authentication path including other nodes; performing multiple pairwise hash calculations on the non-root node and the other nodes to generate candidate root hash values; comparing the candidate root hash values ​​with the stored root hash values; and determining that the integrity of the binary tree graph passes verification when the candidate root value equals the stored root value.
Owner:NXP BV

Method and system for securely reporting and storing computer security profiles

A method for secure storage of cybersecurity data in a blockchain includes: identifying, by a processor of a processing server, a device profile for a computing device; encrypting, by the processor of the processing server, the device profile into an encrypted device profile using a public key of a first cryptographic key pair; encrypting, by the processor of the processing server, the encrypted device profile into a converted device profile via quantum cryptography using a first configuration key; and transmitting, by a transmitter of the processing server, the converted device profile to a blockchain node in a blockchain network.
Owner:MASTERCARD INT INC

An encryption method based on registration keyword strategy hiding

This invention provides a searchable encryption method based on registered keywords and with hidden policies, belonging to the field of cryptography and information security technology. It solves the risks of key escrow and keyword privacy leakage in existing attribute-based search encryption schemes. The technical solution includes the following steps: S1, system initialization; S2, user key generation; S3, user public key validity detection; S4, generation of the system master public key; S5, trapdoor generation; S6, keywords for the encryption access policy; S7, keyword policy detection. This invention utilizes a set of arithmetic and non-double number sequences to construct system common parameters, shortening the parameter length. Simultaneously, it employs a dual-system encryption mechanism to achieve complete security and hides the keyword policy by embedding subgroup elements in the ciphertext, thereby ensuring keyword privacy. While ensuring data confidentiality, this method enables secure and flexible retrieval of encrypted data.
Owner:NANTONG UNIV

A commercial cryptographic digital certificate generation method supporting quantum-resistant cryptography

The application relates to the technical field of information security, in particular to a commercial cipher digital certificate generation method supporting quantum-resistant cipher, which comprises the following steps: a certificate authority generates a hybrid signature self-signed certificate with quantum-resistant cipher signature and traditional public key cipher signature; a user generates a hybrid signature certificate request file and sends the file to the certificate authority; the certificate authority generates a hybrid signature user signature certificate; a key generation center generates a user traditional public key cipher encryption key pair and a user quantum-resistant cipher encryption key pair; the certificate authority generates a hybrid signature user encryption certificate; the certificate authority generates a hybrid encryption public key, a private key encryption ciphertext and a hybrid ciphertext; and the user extracts the hybrid signature signature certificate, the encryption certificate, the quantum-resistant cipher encryption private key and the traditional public key cipher encryption private key, and verifies the signature certificate and the encryption certificate. The application can resist quantum attacks and is compatible with existing digital certificates.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

Quantum-resistant security enhancement method for openid connect

The present application discloses a quantum-resistant security enhancement method for OpenID Connect in a communication network. The method comprises: when communication preprocessing is completed, receiving quantum-resistant token request information sent by a client; generating an access token and an identity token on the basis of the quantum-resistant token request information; generating a temporary key pair associated with the client; acquiring a quantum key identifier; processing the access token to generate a quantum-resistant access token; obtaining a quantum-resistant identity token on the basis of the temporary key pair, the quantum key identifier, post-quantum cryptography and the identity token; sending the quantum-resistant access token and the quantum-resistant identity token to the client; and receiving a resource access request generated on the basis of the quantum-resistant access token and the quantum-resistant identity token, and confirming an access permission to a corresponding resource, such that the client performs resource access on a server. The server and the client encrypt communications by means of post-quantum cryptography and quantum key distribution, thereby significantly enhancing the ability to resist quantum computing attacks.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

SIM (Subscriber Identity Module) card communication and system based on quantum cryptographic algorithm

The invention relates to the technical field of communication security, in particular to an SIM card communication method and system based on an anti-quantum cryptography algorithm, and the method comprises the steps: obtaining first signature data, carrying out the signature verification of the first signature data through employing a public key generated by a first anti-quantum cryptography algorithm and a public key generated by a first cryptographic algorithm, and obtaining a first signature verification result; after the signature verification succeeds, a first preset private key is utilized to perform combined signature on the first random number and a second random number generated by the first SIM card to obtain second signature data; the first SIM card performs signature verification on the second signature data by using the first preset public key; and after successful verification, the first SIM card and the second SIM card communicate based on the symmetric key. According to the application, the anti-quantum cryptographic algorithm is added in the SIM card, so that the post-quantum algorithm can be integrated in the SIM card, the problem that the SIM card uses a traditional cryptographic algorithm is solved, information can be prevented from being attacked and cracked in the quantum computing power era, and the communication security of the SIM card is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Cross trusted authorities identity authentication and message publishing method based on redactable blockchain

The invention discloses a cross trusted authority identity authentication and message publishing method based on redactable blockchain, adopts a redactable blockchain based on chameleon hash function to replace the traditional blockchain, and the trusted authority can use the private key of the chameleon hash function to edit the block content on the blockchain, so that only legal, valid and timely information is stored on the blockchain. In addition, the trusted authority can also edit the vehicle authentication information stored on the blockchain, easily updating the vehicle information credentials or revoking the information credentials of illegal vehicles. In the process of authentication and key negotiation, cryptography tools are used to ensure the confidentiality, integrity and availability of messages, and can effectively resist various known attacks.
Owner:HANGZHOU NORMAL UNIVERSITY