Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

93 results about "Key derivation function" patented technology

In cryptography, a key derivation function (KDF) derives one or more secret keys from a secret value such as a master key, a password, or a passphrase using a pseudorandom function. KDFs can be used to stretch keys into longer keys or to obtain keys of a required format, such as converting a group element that is the result of a Diffie–Hellman key exchange into a symmetric key for use with AES. Keyed cryptographic hash functions are popular examples of pseudorandom functions used for key derivation.

Data encryption method and system based on multi-terminal interaction

The invention discloses a data encryption method and system based on multi-terminal interaction, and relates to data encryption: when a user registers for the first time, acquiring main password data input by the user, and generating main key seed data through a key derivation function according to the main password data; based on the master key seed data, a hierarchical hash algorithm is adopted to construct a key derivation tree data structure, the key derivation tree data structure takes the master key seed data as a root node, and the key derivation tree data structure is expanded layer by layer according to the device category and the device identifier to form a tree-shaped derivation path; when a new device requests authorization, a derivation path is calculated according to the key derivation tree data structure in combination with the attribute data of the corresponding new device, and exclusive key data corresponding to the new device is derived and generated from the master key seed data along the derivation path; according to the exclusive key data of the sending device, in combination with the path data of the receiving device in the key derivation tree, encrypting the data to be transmitted between the devices to generate an encrypted data stream; the encryption efficiency of the offline equipment is improved.
Owner:SHENZHEN YOUQIAN INFORMATION TECH CO LTD +2

Distributed photovoltaic annular communication group key generation method and system

According to the distributed photovoltaic ring communication group key generation method provided by the invention, safe and efficient group key management is realized by combining a group number derivation mechanism, environment feature binding and a quantum key enhancement technology. The method comprises the steps that a preset broadcast root key is called from a concentrator, and the broadcast root key is used for deriving group keys of members in each group; acquiring environment characteristics of members in each group in a communication group corresponding to the concentrator, and recording an acquisition timestamp; summarizing the environmental characteristics of all members in the communication group, and performing hash processing on the summarized environmental characteristics to obtain an initial environmental characteristic vector; and generating a first group key with a preset length through a key derivation function based on the broadcast root key, the initial environment feature vector, the timestamp and a preset group identifier.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +1

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Security key generation and authentication method based on microfluidic DNA detection

The invention discloses a micro-fluidic DNA detection-based security key generation and authentication method, which comprises the following steps: S1, carrying out DNA detection on a biological sample through a micro-fluidic chip to obtain SNP and STR feature data; s2, performing unified coding on the SNP and STR feature data to form stable bit string representation; s3, processing the bit string representation by using a fuzzy extraction mechanism, and generating a consistent key material under the condition of permitting a detection error; s4, deriving a final symmetric key from the key material by using a key derivation function; and S5, performing security packaging, transmission and authentication on the final symmetric key by adopting a post-quantum cryptography mechanism. According to the security key generation and authentication method based on microfluidic DNA detection, a set of key generation and identity authentication scheme with instantaneity, high specificity and anti-quantum security is constructed.
Owner:GUANGDONG UNIV OF TECH

Block chain-based Xiaohua chicken traceability method and system

The invention provides a Xiaohua chicken traceability method and system based on a block chain, and the method comprises the steps: generating a root public parameter and a root verification key through credible setting, generating an independent sub-proof key for each node from breeding to selling through a hierarchical key derivation function based on a traceability hierarchical structure, encoding the acquired multi-modal traceability data into private input of the zero-knowledge proof circuit; selecting a corresponding rule circuit from a predefined circuit library, and splitting a data source party; each data party generates a zero-knowledge proof fragment by using a sub-proof key and a blinding factor, and after a main node verifies public state consistency and blinding factor constraint through a recursive aggregation algorithm, an aggregation proof is generated; the common input comprises a new state commitment generated by a cryptographic accumulator, and continuous updating of the state is realized; and verifying the aggregation certification by using the root verification key, and storing the certification abstract passing the verification in the block chain. According to the invention, cross-link data privacy protection and verifiable chain type tracing can be realized.
Owner:GUANGDONG VOCATIONAL COLLEGE OF SCI & TRADE +2

Method and system for establishing a secure messaging channel between a smartcard and an end device

PendingDE102024129366A1Security arrangementSecuring communicationPersonal identification numberTerminal equipment
A method for establishing a secure messaging channel between a smartcard and an end device is described. The smartcard contains a Personal Identification Number (PIN), an initial key derivation function, and a communication channel establishment protocol. The end device contains the PIN, the initial key derivation function, and the communication channel establishment protocol. The method comprises the following steps: creating an initial key on the smartcard and on the end device based on the PIN and the initial key derivation function; creating a nonce value, which further comprises the following steps: generating the nonce value on one end device or the end device; encrypting the nonce value with the initial key; and sending the encrypted nonce value to the other end device or the smartcard.and decrypting the encrypted nonce value with the first key, executing the communication channel establishment protocol on the smartcard and on the terminal device based on the generated nonce value to generate a second key on the smartcard and on the terminal device, first deriving a first secure messaging channel key on the smartcard and on the terminal device based on the second key, and second deriving a second secure messaging channel key on the smartcard and on the terminal device based on the second key.
Owner:SECUNET SECURITY NETWORKS GMBH

System and method for multi-factor key derivation

A system and method for multi-factor key derivation includes: a user having a plurality of authentication factors; whereby the plurality of authentication factors are converted into key material using intermediate factor-specific functions, and whereby said key material is then converted into a key using a key derivation function.
Owner:MULTIFACTOR INC

Quantum security gateway system

The invention provides a quantum security gateway system, and the system comprises a position obtaining module which is used for obtaining the geographical position information of the quantum security gateway system; the position fingerprint generation module is used for generating a position fingerprint from the geographical position information through a password hash algorithm; the quantum security module is used for acquiring an original quantum key, performing post-processing on the original quantum key by taking the position fingerprint as an input parameter of a key derivation function, generating a quantum key bound with the geographic position, and storing the quantum key bound with the geographic position; the position verification module is used for obtaining the current geographic position when the quantum key bound with the geographic position is used, and calculating the deviation between the current geographic position and the geographic position bound with the quantum key; and the data encryption module is used for determining a security policy according to the deviation. The technical problem that quantum encryption equipment in the prior art is single in security policy dimension and difficult to adapt to security protection requirements of complex environments can be solved.
Owner:SKY SURVEY REMOTE VIEW (XIAN) QUANTUM TECHNOLOGY CO LTD

Firmware updating method, electronic device, server and system

This disclosure relates to a firmware update method, an electronic device, a server, and a system. The method includes: obtaining from a user device an encrypted firmware update package sent by a server to the user device in response to a firmware update request from the electronic device, and a firmware decryption key enDecKey encrypted by the server using a key encryption key KEK, wherein the key encryption key KEK is a temporary key derived based on a predetermined key derivation function; decrypting the received encrypted firmware decryption key enDecKey using the key encryption key KEK to obtain a firmware decryption key decKey; and decrypting the encrypted firmware update package using the firmware decryption key decKey to obtain a firmware update package for updating the firmware in the electronic device.
Owner:TP-LINK INT SHENZHEN CO LTD

Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Owner:THALES SA +1

Key establishment and secure communications based on satellite-connected entropy sources

Systems and techniques for secure communications and distribution of random values, provided via satellite communications, are described. These random values are generated from one or more ground-based entropy sources (e.g., quantum random number generators (QRNGs) at terrestrial locations), and optionally combined with values from satellite-based entropy sources (e.g., QRNGs at non-terrestrial locations). An example method includes: receiving a first random value generated by a first QRNG at a terrestrial location; receiving a second random value and a third random value via at least one satellite communication, each additional random value generated by other QRNGs; and generating a cryptographic key based on the first random value, the second random value, and the third random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Image data encryption transmission method for remote ultrasonic consultation

The invention relates to the technical field of internet encryption, in particular to an image data encryption transmission method for remote ultrasonic consultation, which comprises the following steps: two communication parties exchange respective generated temporary public keys and calculate a shared secret in combination with own private keys, and generate a session shared secret; and calling a key derivation function to perform combined operation on the session shared secret and the session random number to generate a master key. According to the method, the shared secret is generated by using the temporary public key and the local private key through key negotiation in the remote communication process, and the master key is derived in combination with the session random number, so that the dynamic and one-time characteristics of a key generation mechanism are realized, the anti-cracking capability in the data initialization stage is improved, and on the basis of establishing the master key, the security of the system is improved. The structural design of security budget scores is further introduced, resources consumed in the data encryption process are associated with security levels, and a key system with resource perception capability is constructed.
Owner:ZHEJIANG CANCER HOSPITAL

License plate encryption method and device based on differential privacy, system and storage medium

The embodiment of the application provides a license plate encryption method and device based on differential privacy, a system and a storage medium, and relates to the technical field of traffic management. The method comprises the following steps: obtaining an original license plate string and storing the original license plate string; taking a road section identifier and a time slice serial number as a salt value, generating a one-time symmetric key through a key derivation function and a device root key; performing deterministic mapping on the original license plate string by using the one-time symmetric key to generate a fixed-length token; adding noise satisfying a differential privacy standard to the fixed-length token to generate an anonymous token; uploading the anonymous token to a central platform through an encryption channel, and clearing the original license plate string, the fixed-length token and the one-time symmetric key. By generating an anonymous token with spatiotemporal randomness, the anonymous tokens of the same vehicle under different spatiotemporal conditions are not associated with each other, the quantifiable protection of license plate privacy is realized without sacrificing the picture quality, and thus the picture quality and the privacy are taken into account.
Owner:ZHIDAO NETWORK TECH (BEIJING) CO LTD

Bluetooth data transmission encryption method based on intelligent terminal

The application relates to the field of Bluetooth data transmission security technology and discloses a Bluetooth data transmission encryption method based on an intelligent terminal. After the intelligent terminal and a receiving device establish a Bluetooth connection, a temporary session key is generated. A built-in hardware security module of the terminal is accessed to obtain a pre-stored root key. The root key and the temporary session key are used as inputs to generate a session encryption key with higher strength through a key derivation function. The session encryption key is used to encrypt data to be transmitted by using a symmetric encryption algorithm. The hash value of the original transmission data is independently calculated based on a hash function and used as an integrity check code of the data. The encrypted data and the integrity check code are encapsulated and sent to the receiving device through a Bluetooth protocol stack. The application strengthens the security of the key by combining hardware security and dynamic negotiation, and improves the anti-attack ability and reliability of Bluetooth data transmission by adopting an independent integrity check mechanism.
Owner:深圳市乾海芯联科技有限公司 +1

Locking and unlocking the communication interface of electronic devices for powered vehicles.

To lock the communication interface of an electronic device (1) for a powered vehicle, a first identifier (3) is determined, which characterizes a hardware component or a software component of a computing unit (2) on the production line in which the electronic device (1) was produced. A second identifier (4) characterizing the electronic device (1) is obtained. A first input value for a predetermined key derivation function is generated by the computing unit (2) based on the first identifier (3), and a second input value for the key derivation function is generated based on the second identifier (4). A key is generated by the computing unit (2) using the key derivation function based on the first and second input values, and the communication interface is locked using the key.
Owner:CONNAUGHT ELECTRONICS

Communications method and apparatus

A communications method includes receiving, from a second node, first algorithm negotiation request information used to indicate one or more algorithms and one or more key derivation functions, determining at least one first algorithm in the one or more algorithms and at least one first key derivation function in the one or more key derivation functions, and sending, to the second node, first information used to indicate the at least one first algorithm and the at least one first key derivation function.
Owner:HUAWEI TECH CO LTD

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Secure communication method and device for dynamic mode encryption, medium and product

The invention discloses a secure communication method and device for dynamic mode encryption, a medium and a product, and relates to the field of data communication. According to the method, the transmitting end and the receiving end can generate the elliptic curve key pair through the trusted platform module and execute ECDH key negotiation; the sending end sends a detection packet, and the receiving end returns a response packet so as to dynamically adjust the size of the optimal transmission unit according to the network condition; a sending end flexibly selects a single round of AES-GCM encryption or AES-Twoish-Serpent triple chain encryption according to a security level score of a data block, so that the protection strength of sensitive data is ensured, and resource waste caused by excessive encryption of common data is avoided; a sending end generates independent session keys for different data blocks through a key derivation function, the forward security of a communication system is enhanced, an encryption mode and message authentication information are recorded at the frame head of the encrypted data block and encryption protection is carried out, and integrity verification of the transmission process is ensured.
Owner:BEIJING YOU TECHNOLOGY CO LTD

Method and system for hierarchical encryption of multi-type data of 5G new call

The invention relates to the technical field of 5G communication security and service encryption, and discloses a 5G new call multi-type data hierarchical encryption method and system, and the method comprises the steps: obtaining a voice stream and continuous video frames in a 5G new call, and extracting a voice emotion sequence and a video time sequence feature sequence; based on a pre-negotiated master key, the emotion-expression consistency hash value and the timestamp of the time window, generating a consistency binding key through a key derivation function, and forming a cross-modal synchronization key pair; adding an emotion-expression consistency hash value and a cross-modal association feature vector into the encrypted data packet to generate an encrypted data packet group; and the receiving end extracts the cross-modal association feature vector from the encrypted data packet, recalculates the emotion-expression consistency hash value, compares the emotion-expression consistency hash value with the received hash value for verification, and decrypts the data by using the consistency binding key after the verification is passed. According to the invention, deep fusion of encryption protection and multi-modal authenticity verification is realized.
Owner:HANGZHOU FREE TRAVEL INFORMATION TECHNOLOGY CO LTD

Secure parallel upgrading method and system for embedded device firmware based on CAN bus, electronic device and medium

The invention discloses a secure parallel upgrading method and system for firmware of embedded equipment based on a CAN bus, electronic equipment and a medium, and belongs to the field of embedded systems.The secure parallel upgrading method comprises the steps that an equipment management server generates an upgrading data packet; the server generates a temporary session key through a key derivation function, encrypts firmware to be upgraded by using the temporary session key, and then generates a digital signature for encrypted firmware data by using a private key of the server; the server issues the upgrade data packet to the embedded device in parallel through a CAN bus; the embedded device receives the upgrade data packet, derives the same temporary session key by using a preset fixed key and the received random number, verifies the digital signature by using a preset server public key, decrypts the firmware data by using the temporary session key after the verification is passed, and performs integrity verification; and finally, loading and operating the new firmware according to the firmware effective strategy. According to the method, the problems of firmware version synchronization and low serial upgrading speed are solved, and the efficiency and the safety are improved.
Owner:CHENGDU SANLING RUITONG MOBILE COMM CO LTD

Locking and unlocking of communication interface of electronic device of motor vehicle

In order to lock a communication interface of an electronic device (1) of a motor vehicle, a first identifier (3) is determined which characterizes a hardware component of a computing unit (2) of a production line for producing the electronic device (1) or a software component of the computing unit (2). A second identifier (4) characterizing the electronic device (1) is obtained. A first input value for specifying the key derivation function is generated by the computing unit (2) on the basis of the first identifier (3) and a second input value for the key derivation function is generated on the basis of the second identifier (4). A key is generated by the computing unit (2) on the basis of the first input value and the second input value using a key derivation function, and the communication interface is locked using the key.
Owner:CONNAUGHT ELECTRONICS

Method and apparatus for checking the integrity of an executable function of a device unit

The present disclosure relates to a method and an apparatus for checking the integrity of an executable function of a device. The method according to the disclosure comprises a plurality of method steps. An OWF computing function, OWF_R, is executed upon operation-related starting of the device, in particular in an operating / application phase, wherein the executable function is divided into a plurality of boot layers, and wherein a unique device secret, UDS, is read from a memory apparatus and used as an input for the OWF computing function in order to generate two result values: 1) a first result value for a key chain, CDI0, and 2) a second result value for a secure boot verification chain, CDI_sec0. A symmetric proof of authorization, CDI_K0, is determined by executing a key derivation function, KDF, in particular a DICE key derivation function, on the basis of the second value, and the symmetric proof of authorization is used to check the integrity of a first boot layer of the executable function by calculation of an integrity check value, ICV_check. The ICV_check is compared with an integrity reference value, ICV_ref; if there is a match, a further boot layer is loaded for checking, and otherwise an error-containing result is provided for the integrity check.
Owner:SIEMENS AG

Data secure transmission method and device, computer equipment and readable storage medium

The invention relates to a data secure transmission method and device, computer equipment and a readable storage medium. The method comprises the following steps: generating a first key pair and a second key pair according to algorithm negotiation information in an initial stage of communication handshake; parallel negotiation is carried out through the first communication terminal and the second communication terminal, a first shared key and a second shared key are generated based on the first key pair and the second key pair, and the first shared key and the second shared key are combined to obtain a mixed master key; converting the mixed master key into a pseudo-random key by adopting a key derivation function, and generating at least one session key for symmetric encryption by performing iteration processing on the pseudo-random key for multiple times; and encrypting and authenticating application data transmitted between the first communication terminal and the second communication terminal based on the at least one session key and a symmetric encryption algorithm in the algorithm negotiation information. By adopting the method, the anti-attack capability of the master key can be improved, and the confidentiality and integrity of data transmission are met while the communication security is guaranteed.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Database access control method and computer device

PendingCN122286835AHash functionEngineering
This application provides a database access control method and computer device. The method first receives a privileged access request and generates a request digest and session identifier to determine the session validity period. Then, after the approval node completes valid signing, a threshold authorization token is generated. Next, an alias seed is generated using a key derivation function with an alias root key and multiple authorization information including at least the threshold authorization token and session identifier. Based on this seed, a transient access alias and a role lease identifier are derived using a hash message authentication code and a hash function, respectively. Finally, a zero-resident privileged session is established based on the transient access alias, role lease identifier, and session validity period, valid only in the current session. The transient access alias and role lease identifier are reclaimed when the session ends or a revocation condition is triggered. Through these steps, security risks are reduced, and on-demand, dynamic, and revocable database privileged access control is achieved, significantly improving database access security.
Owner:JIUYOU TECH (SHENZHEN) CO LTD

Directional Key Derivation and Targeted Key Management for Encrypted Links in a UALink Network

As AI accelerator pods scale to hundreds of accelerators connected through encrypted switches, some implementations for directional key derivation and targeted key management on encrypted links, include a circuit configured to derive encryption keys using a key derivation function with a context value that includes a device pair type field. The device pair type field has different values for the accelerator-to-switch direction and the switch-to-accelerator direction, producing mathematically distinct encryption keys for each direction on the same physical link. Some implementations further include a key management message format comprising a target type field indicating whether a key operation targets an accelerator or a switch. When an accelerator receives a key management message targeting a switch, the accelerator drops the message and signals an error. When a switch with collective security enabled receives a key management message targeting a switch, the switch performs the specified key operation.
Owner:UNIFABRIX LTD

Controller and its safe operation method and system

The application relates to the technical field of embedded systems, and provides a controller and a safe operation method and system thereof. The method is applied to a controller without a hardware security module, and comprises the following steps: obtaining device unique characteristic information of the controller; generating a device root key through a key derivation function based on the device unique characteristic information; wherein the device root key exists in a volatile memory; deriving a function key based on the device root key; and performing a safe operation on target data by using the function key. The safe operation of the controller is realized by combining the device unique characteristic information in a software mode, and security threats such as firmware tampering and data leakage are effectively resisted.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

A method, device and medium for security authentication of a PostgreSQL database

PendingCN122634644AKey serverPassword
This specification discloses a method, device, and medium for secure authentication of a PostgreSQL database, relating to the field of security authentication technology, and is used to solve the problem of unauthorized login and unauthorized covert login caused by user password leakage, which is difficult to address with existing authentication methods. The method includes: a client receiving a username and password input by a user, and generating a first communication key using a key derivation function by combining the username, the password, a first preset password, and a first count value; a server receiving a username sent by the client, querying the PostgreSQL database to obtain the corresponding stored password, a second preset password, and a second count value, and generating a second communication key using the key derivation function; and the server receiving the first communication key and performing password authentication based on the first and second communication keys to obtain the authentication result of the PostgreSQL database.
Owner:HIGHGO SOFTWARE