Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

130 results about "Key derivation function" patented technology

In cryptography, a key derivation function (KDF) derives one or more secret keys from a secret value such as a master key, a password, or a passphrase using a pseudorandom function. KDFs can be used to stretch keys into longer keys or to obtain keys of a required format, such as converting a group element that is the result of a Diffie–Hellman key exchange into a symmetric key for use with AES. Keyed cryptographic hash functions are popular examples of pseudorandom functions used for key derivation.

Key establishment and secure communications based on satellite-connected entropy sources

Systems and techniques for secure communications and distribution of random values, provided via satellite communications, are described. These random values are generated from one or more ground-based entropy sources (e.g., quantum random number generators (QRNGs) at terrestrial locations), and optionally combined with values from satellite-based entropy sources (e.g., QRNGs at non-terrestrial locations). An example method includes: receiving a first random value generated by a first QRNG at a terrestrial location; receiving a second random value and a third random value via at least one satellite communication, each additional random value generated by other QRNGs; and generating a cryptographic key based on the first random value, the second random value, and the third random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

Jewelry transaction data security and privacy protection method based on 5G fusion application

The invention discloses a jewelry transaction data security and privacy protection method based on a 5G fusion application. The method comprises the following steps: establishing a distributed database; generating a first transaction public key and a first transaction private key of two transaction parties through a pre-established first asymmetric encryption algorithm; carrying out random multivariate function calculation on the first transaction public key and the first transaction private key of the two transaction parties, and desensitizing the random multivariate function through an encryption algorithm and storing the random multivariate function in a distributed database; solving a random seed of the random multivariate function as a second transaction private key of the two transaction parties through a key derivation function of a second Hash algorithm; in the encryption period, the transaction data of the two transaction parties are encrypted through an encryption algorithm, and meanwhile, the encrypted data are desensitized and stored; in the decryption period, the two transaction parties obtain plaintext data through the second transaction private key; on the basis of an existing encryption algorithm, the neural network algorithm is introduced to generate the purchaser key, and meanwhile, desensitization processing is performed on the ciphertext data, so that jewelry transaction data is safer.
Owner:GUANGDONG JEWELRY & JADE EXCHANGE CENT CO LTD

Data encryption method and system based on multi-terminal interaction

The invention discloses a data encryption method and system based on multi-terminal interaction, and relates to data encryption: when a user registers for the first time, acquiring main password data input by the user, and generating main key seed data through a key derivation function according to the main password data; based on the master key seed data, a hierarchical hash algorithm is adopted to construct a key derivation tree data structure, the key derivation tree data structure takes the master key seed data as a root node, and the key derivation tree data structure is expanded layer by layer according to the device category and the device identifier to form a tree-shaped derivation path; when a new device requests authorization, a derivation path is calculated according to the key derivation tree data structure in combination with the attribute data of the corresponding new device, and exclusive key data corresponding to the new device is derived and generated from the master key seed data along the derivation path; according to the exclusive key data of the sending device, in combination with the path data of the receiving device in the key derivation tree, encrypting the data to be transmitted between the devices to generate an encrypted data stream; the encryption efficiency of the offline equipment is improved.
Owner:SHENZHEN YOUQIAN INFORMATION TECH CO LTD +2

Key establishment and secure communications based on satellite entropy sources

Systems and techniques for secure communications and distribution of random values, produced from at least two satellite entropy sources, are described. These random values may be provided by respective quantum random number generators (QRNGs) at separate satellites, and optionally combined with values from ground-based entropy sources (e.g., QRNGs at terrestrial locations). An example method includes: receiving a first random value and a second random value via at least one satellite communication, where the first random value is generated by a first QRNG at a first satellite, and the second random value is generated by a second QRNG at a second satellite; and generating a cryptographic key based on the first random value and the second random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

Systems and methods for utilizing machine learning models to generate encryption keys

A device may receive input key material, and may process the input key material, with a trained generative adversarial network (GAN) model, to generate an encryption key with a maximized entropy. The trained GAN model may include a key generator network model trained to generate encryption keys that generalize key derivation functions with higher entropy to enhance cryptographic security, and a key discriminator network model trained to predict authenticities of the encryption keys generated by the key generator network model. The device may perform one or more actions based on the encryption key.
Owner:VERIZON PATENT & LICENSING INC

Data enhancement encryption method, system and equipment based on AES (Advanced Encryption Standard) and medium

The invention provides an AES (Advanced Encryption Standard)-based data enhancement encryption method, system and equipment and a medium, and belongs to the technical field of data security. The method comprises the following steps: receiving plaintext data to be encrypted and a password provided by a user; deriving a master key and an HMAC key from the password and the randomly generated salt value by using a key derivation function; randomly generating an initialization vector, and encrypting the plaintext data through the master key by using an AES encryption mode to obtain encrypted ciphertext data; performing message authentication code calculation on the ciphertext data, the initialization vector and the salt value through an HMAC key to generate an HMAC check value; and combining the salt value, the initialization vector, the ciphertext data and the HMAC verification value into a final output encrypted data packet. According to the method, a series of enhancement mechanisms such as strong key derivation, random salt values, message authentication codes and initialization vectors are introduced, so that the security and integrity of data are further improved.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Distributed photovoltaic annular communication group key generation method and system

According to the distributed photovoltaic ring communication group key generation method provided by the invention, safe and efficient group key management is realized by combining a group number derivation mechanism, environment feature binding and a quantum key enhancement technology. The method comprises the steps that a preset broadcast root key is called from a concentrator, and the broadcast root key is used for deriving group keys of members in each group; acquiring environment characteristics of members in each group in a communication group corresponding to the concentrator, and recording an acquisition timestamp; summarizing the environmental characteristics of all members in the communication group, and performing hash processing on the summarized environmental characteristics to obtain an initial environmental characteristic vector; and generating a first group key with a preset length through a key derivation function based on the broadcast root key, the initial environment feature vector, the timestamp and a preset group identifier.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +1

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Secret key extraction for line-of-sight communications

Methods, systems, and devices for wireless communications are described. Communication devices may perform secret key generation using a set of line-of-sight (LOS) communication modes to secure a physical channel. For example, a first device and a second device may communicate a set of reference signals over the physical channel using a set of LOS communication modes. The first device and the second device may generate a secret key based on the set of LOS communication modes, for example, by using information associated with the set of LOS communication modes to compute the secret key using a key derivation function that outputs the secret key. The first device and the second device may secure the physical channel by encrypting signaling between the first device and the second device with the secret key and communicating the signaling over the physical channel using LOS communications.
Owner:QUALCOMM INC

Security key generation and authentication method based on microfluidic DNA detection

The invention discloses a micro-fluidic DNA detection-based security key generation and authentication method, which comprises the following steps: S1, carrying out DNA detection on a biological sample through a micro-fluidic chip to obtain SNP and STR feature data; s2, performing unified coding on the SNP and STR feature data to form stable bit string representation; s3, processing the bit string representation by using a fuzzy extraction mechanism, and generating a consistent key material under the condition of permitting a detection error; s4, deriving a final symmetric key from the key material by using a key derivation function; and S5, performing security packaging, transmission and authentication on the final symmetric key by adopting a post-quantum cryptography mechanism. According to the security key generation and authentication method based on microfluidic DNA detection, a set of key generation and identity authentication scheme with instantaneity, high specificity and anti-quantum security is constructed.
Owner:GUANGDONG UNIV OF TECH

Construction method of hybrid key encapsulation mechanism

The invention discloses a construction method of a hybrid key encapsulation mechanism, which comprises the following steps of: generating a public and private key pair of two PKE (Public Key Exchange) algorithms based on security parameters, and outputting a public and private key pair of the hybrid key encapsulation mechanism; taking a public key of a mixed key encapsulation mechanism as the input of an encapsulation algorithm, randomly selecting two plaintexts, respectively generating ciphertexts through public key encryption algorithms of two PKE algorithms, deriving a shared key through a key derivation function, and outputting the shared key; and taking the ciphertext and the private key of the mixed key encapsulation mechanism as the input of a de-encapsulation algorithm, and outputting a shared key. According to the method, a construction method based on the KEM is not used any more, universal construction of the hybrid KEM based on the PKE scheme is achieved, multiple PKE schemes can be adopted for instantiation, multi-level safety under classical and quantum models is achieved, a key derivation function of the KEM for achieving CPA and CCA safety only depends on a plaintext part, and therefore the key derivation function of the hybrid KEM is independent of the plaintext part. Running efficiency is improved by simplifying hash operations and removing redundant hash operations.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Block chain-based Xiaohua chicken traceability method and system

The invention provides a Xiaohua chicken traceability method and system based on a block chain, and the method comprises the steps: generating a root public parameter and a root verification key through credible setting, generating an independent sub-proof key for each node from breeding to selling through a hierarchical key derivation function based on a traceability hierarchical structure, encoding the acquired multi-modal traceability data into private input of the zero-knowledge proof circuit; selecting a corresponding rule circuit from a predefined circuit library, and splitting a data source party; each data party generates a zero-knowledge proof fragment by using a sub-proof key and a blinding factor, and after a main node verifies public state consistency and blinding factor constraint through a recursive aggregation algorithm, an aggregation proof is generated; the common input comprises a new state commitment generated by a cryptographic accumulator, and continuous updating of the state is realized; and verifying the aggregation certification by using the root verification key, and storing the certification abstract passing the verification in the block chain. According to the invention, cross-link data privacy protection and verifiable chain type tracing can be realized.
Owner:GUANGDONG VOCATIONAL COLLEGE OF SCI & TRADE +2

Method and system for establishing a secure messaging channel between a smartcard and an end device

A method for establishing a secure messaging channel between a smartcard and an end device is described. The smartcard contains a Personal Identification Number (PIN), an initial key derivation function, and a communication channel establishment protocol. The end device contains the PIN, the initial key derivation function, and the communication channel establishment protocol. The method comprises the following steps: creating an initial key on the smartcard and on the end device based on the PIN and the initial key derivation function; creating a nonce value, which further comprises the following steps: generating the nonce value on one end device or the end device; encrypting the nonce value with the initial key; and sending the encrypted nonce value to the other end device or the smartcard.and decrypting the encrypted nonce value with the first key, executing the communication channel establishment protocol on the smartcard and on the terminal device based on the generated nonce value to generate a second key on the smartcard and on the terminal device, first deriving a first secure messaging channel key on the smartcard and on the terminal device based on the second key, and second deriving a second secure messaging channel key on the smartcard and on the terminal device based on the second key.
Owner:SECUNET SECURITY NETWORKS GMBH

System and method for multi-factor key derivation

A system and method for multi-factor key derivation includes: a user having a plurality of authentication factors; whereby the plurality of authentication factors are converted into key material using intermediate factor-specific functions, and whereby said key material is then converted into a key using a key derivation function.
Owner:MULTIFACTOR INC

Quantum security gateway system

The invention provides a quantum security gateway system, and the system comprises a position obtaining module which is used for obtaining the geographical position information of the quantum security gateway system; the position fingerprint generation module is used for generating a position fingerprint from the geographical position information through a password hash algorithm; the quantum security module is used for acquiring an original quantum key, performing post-processing on the original quantum key by taking the position fingerprint as an input parameter of a key derivation function, generating a quantum key bound with the geographic position, and storing the quantum key bound with the geographic position; the position verification module is used for obtaining the current geographic position when the quantum key bound with the geographic position is used, and calculating the deviation between the current geographic position and the geographic position bound with the quantum key; and the data encryption module is used for determining a security policy according to the deviation. The technical problem that quantum encryption equipment in the prior art is single in security policy dimension and difficult to adapt to security protection requirements of complex environments can be solved.
Owner:SKY SURVEY REMOTE VIEW (XIAN) QUANTUM TECHNOLOGY CO LTD

Firmware updating method, electronic device, server and system

This disclosure relates to a firmware update method, an electronic device, a server, and a system. The method includes: obtaining from a user device an encrypted firmware update package sent by a server to the user device in response to a firmware update request from the electronic device, and a firmware decryption key enDecKey encrypted by the server using a key encryption key KEK, wherein the key encryption key KEK is a temporary key derived based on a predetermined key derivation function; decrypting the received encrypted firmware decryption key enDecKey using the key encryption key KEK to obtain a firmware decryption key decKey; and decrypting the encrypted firmware update package using the firmware decryption key decKey to obtain a firmware update package for updating the firmware in the electronic device.
Owner:TP-LINK INT SHENZHEN CO LTD

Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Owner:THALES SA +1

Key establishment and secure communications based on satellite-connected entropy sources

Systems and techniques for secure communications and distribution of random values, provided via satellite communications, are described. These random values are generated from one or more ground-based entropy sources (e.g., quantum random number generators (QRNGs) at terrestrial locations), and optionally combined with values from satellite-based entropy sources (e.g., QRNGs at non-terrestrial locations). An example method includes: receiving a first random value generated by a first QRNG at a terrestrial location; receiving a second random value and a third random value via at least one satellite communication, each additional random value generated by other QRNGs; and generating a cryptographic key based on the first random value, the second random value, and the third random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

AES-based data enhancement encryption method, system, device and medium

The present invention provides a data enhancement encryption method, system, device, and medium based on AES, belonging to the field of data security technology. The method comprises: receiving plaintext data to be encrypted and a password provided by a user; deriving a master key and an HMAC key from the password and a randomly generated salt value using a key derivation function; randomly generating an initialization vector, and encrypting the plaintext data using the master key using the AES encryption mode to obtain encrypted ciphertext data; performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value using the HMAC key to generate an HMAC check value; and combining the salt value, the initialization vector, the ciphertext data, and the HMAC check value into a final output encrypted data packet. The present invention further improves the security and integrity of data by introducing a series of enhancement mechanisms such as strong key derivation, random salt value, message authentication code, and initialization vector.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Dual-mode bluetooth pairing

A method of enabling dual-mode Bluetooth pairing between a first electronic device and a second electronic device is executed by the first electronic device and comprises: receiving, from the second electronic device: an enablement request to enable dual-mode Bluetooth pairing between the first electronic device and the second electronic device, wherein dual-mode Bluetooth pairing comprises generating a first pairing key and applying a key derivation function to an input comprising the first pairing key to generate a second pairing key; and verification data; determining, by the first electronic device, whether the verification data meets a predetermined verification criterion; and in response to a determination that the verification data meets the predetermined verification criterion, enabling dual-mode Bluetooth pairing between the first electronic device and the second electronic device.
Owner:DYSON TECH LTD

Image data encryption transmission method for remote ultrasonic consultation

The invention relates to the technical field of internet encryption, in particular to an image data encryption transmission method for remote ultrasonic consultation, which comprises the following steps: two communication parties exchange respective generated temporary public keys and calculate a shared secret in combination with own private keys, and generate a session shared secret; and calling a key derivation function to perform combined operation on the session shared secret and the session random number to generate a master key. According to the method, the shared secret is generated by using the temporary public key and the local private key through key negotiation in the remote communication process, and the master key is derived in combination with the session random number, so that the dynamic and one-time characteristics of a key generation mechanism are realized, the anti-cracking capability in the data initialization stage is improved, and on the basis of establishing the master key, the security of the system is improved. The structural design of security budget scores is further introduced, resources consumed in the data encryption process are associated with security levels, and a key system with resource perception capability is constructed.
Owner:ZHEJIANG CANCER HOSPITAL

License plate encryption method and device based on differential privacy, system and storage medium

The embodiment of the application provides a license plate encryption method and device based on differential privacy, a system and a storage medium, and relates to the technical field of traffic management. The method comprises the following steps: obtaining an original license plate string and storing the original license plate string; taking a road section identifier and a time slice serial number as a salt value, generating a one-time symmetric key through a key derivation function and a device root key; performing deterministic mapping on the original license plate string by using the one-time symmetric key to generate a fixed-length token; adding noise satisfying a differential privacy standard to the fixed-length token to generate an anonymous token; uploading the anonymous token to a central platform through an encryption channel, and clearing the original license plate string, the fixed-length token and the one-time symmetric key. By generating an anonymous token with spatiotemporal randomness, the anonymous tokens of the same vehicle under different spatiotemporal conditions are not associated with each other, the quantifiable protection of license plate privacy is realized without sacrificing the picture quality, and thus the picture quality and the privacy are taken into account.
Owner:ZHIDAO NETWORK TECH (BEIJING) CO LTD

Bluetooth data transmission encryption method based on intelligent terminal

The application relates to the field of Bluetooth data transmission security technology and discloses a Bluetooth data transmission encryption method based on an intelligent terminal. After the intelligent terminal and a receiving device establish a Bluetooth connection, a temporary session key is generated. A built-in hardware security module of the terminal is accessed to obtain a pre-stored root key. The root key and the temporary session key are used as inputs to generate a session encryption key with higher strength through a key derivation function. The session encryption key is used to encrypt data to be transmitted by using a symmetric encryption algorithm. The hash value of the original transmission data is independently calculated based on a hash function and used as an integrity check code of the data. The encrypted data and the integrity check code are encapsulated and sent to the receiving device through a Bluetooth protocol stack. The application strengthens the security of the key by combining hardware security and dynamic negotiation, and improves the anti-attack ability and reliability of Bluetooth data transmission by adopting an independent integrity check mechanism.
Owner:深圳市乾海芯联科技有限公司 +1

System access using mobile devices

Embodiments of the present disclosure relate to system access using a mobile device. The present invention discloses techniques related to electronic security, such as for authenticating a mobile electronic device to allow access to system functions (e.g., physical access to the system, starting the engine / motor, etc.). In some embodiments, the system and the mobile device exchange public keys of a public key pair during a pairing process. In some embodiments, an asymmetric transaction process includes using a key derivation function to generate a shared secret based on a key established using a secure key exchange (e.g., Elliptic Curve Diffie-Hellman) and verifying the signature of the system before transmitting any information identifying the mobile device. In various embodiments, the disclosed techniques can increase transaction security and the privacy of identification information.
Owner:APPLE INC

Locking and unlocking the communication interface of electronic devices for powered vehicles.

To lock the communication interface of an electronic device (1) for a powered vehicle, a first identifier (3) is determined, which characterizes a hardware component or a software component of a computing unit (2) on the production line in which the electronic device (1) was produced. A second identifier (4) characterizing the electronic device (1) is obtained. A first input value for a predetermined key derivation function is generated by the computing unit (2) based on the first identifier (3), and a second input value for the key derivation function is generated based on the second identifier (4). A key is generated by the computing unit (2) using the key derivation function based on the first and second input values, and the communication interface is locked using the key.
Owner:CONNAUGHT ELECTRONICS

Communications method and apparatus

A communications method includes receiving, from a second node, first algorithm negotiation request information used to indicate one or more algorithms and one or more key derivation functions, determining at least one first algorithm in the one or more algorithms and at least one first key derivation function in the one or more key derivation functions, and sending, to the second node, first information used to indicate the at least one first algorithm and the at least one first key derivation function.
Owner:HUAWEI TECH CO LTD

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3