Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

747 results about "Key distribution" patented technology

In symmetric key cryptography, both parties must possess a secret key which they must exchange prior to using any encryption. Distribution of secret keys has been problematic until recently, because it involved face-to-face meeting, use of a trusted courier, or sending the key through an existing encryption channel. The first two are often impractical and always unsafe, while the third depends on the security of a previous key exchange.

Industrial internet data security communication method based on hybrid anti-quantum cryptography

The invention discloses an industrial internet data security communication method based on hybrid anti-quantum cryptography, which relates to the technical field of data communication, and comprises the following steps: acquiring a key pair and an anti-quantum security certificate; sending a connection request to data receiver equipment to complete certificate credibility authentication, and sending an anti-quantum security certificate of the equipment; receiving a shared key seed sent by the data receiver equipment; decrypting the encapsulated ciphertext to obtain a shared key seed, and generating a corresponding shared key according to the same shared key generation algorithm as the data receiver equipment; the method comprises the following steps of: signing original data by using a signature private key, splicing a signature and the original data to obtain spliced data, encrypting the spliced data by using a shared key based on an AES-256-GCM algorithm to obtain an encrypted ciphertext and an ML-DSA signature, and sending the encrypted ciphertext to data receiver equipment. According to the method, the key distribution step is simplified, the signature verification calculation overhead is optimized, and the data communication efficiency is improved.
Owner:SICHUAN UNIV +1

Quantum key distribution secure communication system based on quantum mechanics principle

The invention relates to the technical field of quantum communication security, and discloses a quantum key distribution secure communication system based on a quantum mechanics principle. The system comprises a quantum state preparation unit which controls a quantum emission device to output a quantum state sequence containing a preset polarization angle and a phase modulation photon group; a quantum channel feature extraction unit captures channel environment interference parameters and constructs a photon polarization distribution matrix; a quantum communication security evaluation unit receives the matrix, and calculates a channel security coefficient threshold through a quantum bit error rate analyzer; the quantum key dynamic optimization unit generates an optimized key segmentation strategy in combination with a security coefficient threshold and a historical key negotiation record; the quantum key rotation control unit switches quantum state modulation parameters according to a segmentation strategy and a time window; and the quantum node synchronization management unit monitors node clock offset and injects a calibration signal to realize key distribution time slot alignment. The system can dynamically cope with environmental interference, and improves the security and adaptability of quantum key distribution.
Owner:PANZHIHUA UNIV

Data encryption system for evidence collection and storage based on block chain technology

The invention relates to the technical field of block chains, and discloses a data encryption system for evidence collection and storage based on a block chain technology. According to the data encryption system for evidence collection and storage based on the block chain technology, a hash value can be generated based on a timestamp of data chaining, so that integrity of storage data is regulated and controlled, data tampering detection is realized, a user permission access range can be regulated and controlled in combination with a key distribution mechanism, sensitive data leakage is effectively prevented, and user experience is improved. The consistency of the encryption step is verified according to the intelligent contract execution logic, the multi-node synchronization error is eliminated, the error of the encrypted data storage link is verified through the Hash verification algorithm, and the consistency of the block data is ensured.
Owner:薄同言

Power distribution automation terminal safety debugging method based on Bluetooth communication

The invention provides a power distribution automation terminal security debugging method based on Bluetooth communication, and the method comprises the steps: extracting a historical operation record and a current task context from an operator identity identifier, calculating a real-time permission range of resource access, and adjusting an initial access boundary according to the real-time permission range; a security gateway module is embedded in a Bluetooth communication channel, a cross-domain data exchange request is intercepted and analyzed, whether the request exceeds the adjusted access boundary is judged, and if yes, transmission is refused; analyzing the cross-domain data exchange request, extracting a source domain identifier and a target domain identifier of a data packet from the cross-domain data exchange request, and encrypting the data packet to obtain encrypted cross-domain transmission data; and obtaining a decryption key distribution record of the encrypted cross-domain transmission data in the security domain of the receiving end, judging whether the key is matched or not, if so, decrypting the data and transmitting the data to the target domain, and otherwise, discarding the data.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

High-load data steganography method, system, equipment and medium

The invention discloses a high-load data steganography method, system and device and a medium, and the method comprises the steps: obtaining secret data of a power system, and converting the secret data into a novenary sequence; a quantum key distribution system is utilized to generate a shared key, the novenary sequence is encrypted through an encryption key, encrypted information is obtained, and the shared key comprises the encryption key and a mapping key; determining a corresponding first unit matrix from a preset mapping library based on the mapping key, and performing non-overlapping tiling on the first unit matrix in a two-dimensional plane to obtain a second-order reference matrix; and scanning a preset carrier image into a non-overlapping first pixel pair sequence according to a Hilbert curve, and embedding the encrypted information into the first pixel pair sequence by using the second-order reference matrix to obtain a steganographic image, so that the data transmission security can be improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Client information encryption protection method in pork transaction process

The invention relates to the technical field of information encryption, in particular to a customer information encryption protection method in a pork transaction process, which comprises the following steps of: based on pork transaction data, sequentially finishing key distribution path sorting and serial number verification, screening deviation in combination with customer operation behaviors, adjusting a sensitive field encryption strategy and replacing a key; and performing consistency verification on the identity data abstract combination, generating a signature according to the transaction content, and verifying a signature consistency result. In the invention, through a dynamic key path and inter-node sorting coding, real-time adjustment of a flow link is realized, transaction behavior data drives an encryption strategy to be switched in time, a sensitive field key can be dynamically updated along with the change of an operation characteristic, and segmentation consistency confirmation of a client identity is realized through multi-abstract combination cross verification; digital signatures are synchronously incorporated into double check of multi-source abstracts and transaction contents, and when behavior abnormity and node abnormity are found, related processes are actively interrupted, and risk marking is automatically completed.
Owner:BEIJING ZHONGNONG YIJIA RESOURCES TECH CO LTD

System and method for point-to-point decoy differential phase shift (DPS) quantum key distribution (QKD)

Embodiments of a present disclosure relate to communication systems and more particularly to a system and a method for a point-to-point decoy differential phase shift (DPS) Quantum Key Distribution (QKD). The system includes a source QKD device and a destination QKD device. The source QKD device generates and transmits one or more quantum states comprising a series of N coherent pulses with one or more phases to the destination QKD device. The destination QKD device receives, and records time information and corresponding detector units associated with each photon detection event in the received quantum states. The source and destination QKD devices use decoy states to detect and prevent attacks, such as Photon-Number-Splitting (PNS) attacks. The system allows for the secure generation of a secret key between the source and destination QKD devices.
Owner:QUNU LABS PTE LTD

Intelligent management method for power marketing archives

The invention provides a power marketing archive intelligent management method, which comprises the steps of receiving archive data through a power data acquisition interface, matching an electricity price feature code in an archive based on a real-time electricity price policy identifier, and injecting a version calibration mark into unmatched data; constructing an electricity consumption abnormity prediction model based on the user historical load mode and the environmental factors; when a query request is responded, dynamic penalty parameters are generated based on the user behavior portrait and the rule base; a quantum key distribution path is generated based on a power grid topological structure, and cascade encryption is implemented along physical connection nodes; dynamically associating user operation authority with a power grid operation risk signal, and automatically disabling core operation in a high-risk state; and analyzing archive data in a security isolation environment to drive line loss optimization, electric charge tracing and fault pre-judgment service flow in real time, and outputting feedback archive update based on the service. According to the invention, the safety, reliability and operation efficiency of power marketing archive management are improved.
Owner:INNER MONGOLIA ELECTRIC POWER (GRP) CO LTD DIGITAL RES BRANCH

Selectable Encryption for 5G Open Radio Access Network

Techniques for encrypting data within a 5G Open Radio Access Network (O-RAN) includes receiving, at a first module of the 5G O-RAN, a first set of one or more data packets encrypted using mathematical encryption. The method also includes determining, using a machine-learning model trained to detect cybersecurity threats, the existence of a cybersecurity threat associated with the voice or data transaction, and in response, determining to switch encryption from the mathematical encryption to quantum encryption. The method further includes encrypting the one or more data packets using a quantum encryption key to generate quantum-encrypted data packets, transmitting the quantum encryption key from the first module of the 5G O-RAN core to a second module of the 5G O-RAN over a quantum key distribution (QKD) channel, and transmitting the quantum-encrypted data packets from the first module of the 5G O-RAN to the second module of the 5G O-RAN.
Owner:BOOST SUBSCRIBERCO LLC

Extension of network control system into public cloud

Some embodiments provide a method for a first data compute node (DCN) operating in a public datacenter. The method receives an encryption rule from a centralized network controller. The method determines that the network encryption rule requires encryption of packets between second and third DCNs operating in the public datacenter. The method requests a first key from a secure key storage. Upon receipt of the first key, the method uses the first key and additional parameters to generate second and third keys. The method distributes the second key to the second DCN and the third key to the third DCN in the public datacenter.
Owner:VMWARE INC

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Key sharing and detection scheme based on intelligent electric meter

The invention discloses a key sharing and security detection scheme based on an intelligent electric meter, and aims to solve the problems that an untrusted electric meter in an intelligent power grid is difficult to identify effectively, the detection scale is uncontrollable and the communication security is insufficient. According to the scheme, the elliptic curve cryptography, the threshold secret sharing mechanism and the physical unclonable function are combined, and hardware-level binding of the unique identity of the equipment and the secret key is achieved in the registration stage. Through a threshold password mechanism, a plurality of intelligent electric meters cooperatively participate in key reconstruction and encryption communication, and the intelligent electric meters can still work normally when part of the electric meters fail or are broken through. The center node can actively identify a fault or a malicious ammeter and dynamically adjust a communication strategy according to the integrity and correctness of the feedback information. Meanwhile, the scheme supports dynamic identity updating and integrity verification, and effectively resists modeling attacks, Sybil attacks, replay attacks and DoS / DDoS attacks. According to the invention, secure identity authentication, reliable key distribution and efficient anomaly detection are realized, and the security of smart grid terminal communication is improved.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

All-in-one machine encryption communication transmission method and system based on dynamic strategy

The invention relates to the technical field of communication transmission, and particularly discloses an all-in-one machine encryption communication transmission method and system based on a dynamic strategy, and the method comprises the steps: collecting hardware state parameters, network environment parameters and communication content characteristics of an all-in-one machine and a target communication opposite end in real time; calculating a risk index of the current communication process based on the network environment parameters of the all-in-one machine and the target communication opposite terminal; matching an encryption algorithm sequence, a key updating frequency and a transmission protocol according to hardware state parameters, risk indexes and communication content characteristics of the all-in-one machine and a target communication opposite end, performing segmented encryption and multi-channel parallel transmission on communication data of the all-in-one machine, and performing security key distribution in combination with a distributed key management mechanism to obtain a security key; performing encrypted communication security verification based on the security key to obtain communication verification data; the security of the communication process of the all-in-one machine is improved, and the risks of data leakage and man-in-the-middle attack are prevented.
Owner:JINJI FUTURE (SHENZHEN) TECHNOLOGY CO LTD

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Network communication dynamic encryption method, encryption and decryption system, equipment, medium and product

The invention discloses a network communication dynamic encryption method, an encryption and decryption system, equipment, a medium and a product, and relates to the technical field of communication. The method comprises the steps that a dynamic factor is obtained through a Berkley packet filter function, a key is generated based on the dynamic factor, the key generated based on the dynamic factor has high randomness and unpredictability, and the problem that a fixed key is adopted in a traditional encryption mode, and consequently the key is prone to being cracked can be solved; moreover, by using the execution environment of the Berkley packet filter function in the kernel mode, the risk that the key is stolen in the transmission and storage process is reduced, the influence on the network communication performance is small, and the network communication encryption efficiency and the network communication security are improved. Moreover, the information of network communication is used as the basis of key generation, additional key distribution and storage management processes are not needed, complex key exchange and certificate management mechanisms are not needed, the key management process is simplified, and the operation and maintenance cost of the system is reduced.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Block chain cross-domain service method and system based on sharing verification and smart contract

The invention discloses a block chain cross-domain service method and system based on sharing verification and a smart contract, and the method comprises the steps: building a cross-domain sharing channel between a first business domain of a first block chain and a second business domain of a second block chain through a main node on a relay chain; performing hash operation on the original data to obtain a data fingerprint, packaging the data fingerprint, the data metadata and the digital signature of the data holding node into a first message, and submitting the first message to a relay chain through a sharing channel; after receiving the first message, performing consensus verification on the data fingerprint based on a threshold signature mechanism, and writing a verification result into a shared state table; querying the verification state of the data fingerprint from the sharing state table through the data use node in the second service domain, and requesting to download the encrypted data from the intelligent contract of the relay chain; executing permission judgment, and triggering a key distribution contract to transmit a decryption key to a data use node; and downloading the encrypted data, and writing the cross-domain data sharing transaction record into a block chain account book of the second business domain.
Owner:CHINESE PEOPLES LIBERATION ARMY INFORMATION SUPPORT CORPS ENGINEERING UNIVERSITY

Multi-level security protection method taking persistent memory as core level

The invention discloses a multi-level security protection method taking a persistent memory as a core level, and relates to the technical field of computer storage security. The method comprises the following steps: constructing a cross-level security abstract model, and implementing NUMA perception encryption on the basis of the cross-level security abstract model, including a localization encryption strategy and an intelligent key distribution system; based on a cross-hierarchy security abstract model and NUMA perception encryption, dynamic key hierarchical derivation is realized, a tree topology structure is adopted in the derivation process, generation of a root key and sub-keys of each hierarchy depends on a hierarchical key derivation engine, and cross-node synchronization is completed through an intelligent key distribution system during key cascade update; a side channel attack resisting system is constructed, support for CXL equipment is matched with establishment of a CXL metadata consistency group in NUMA perception encryption, and the security of data transmission and storage of the CXL equipment is guaranteed. According to the invention, the encryption performance is obviously improved.
Owner:Shanxi Taihang Laboratory Co., Ltd.

Vehicle-mounted controller encryption communication method

The invention discloses an encryption communication method for a vehicle-mounted controller, which relates to the technical field of encryption communication, and comprises the following steps: remarkably improving the synchronization efficiency, dynamically screening relay nodes by weight, greatly reducing the key distribution flow, avoiding broadcast storm under large-scale formation, and ensuring the real-time performance of vehicle cooperative control. Attack resistance is enhanced, a chaotic timestamp is fused with multi-source noise and clock disturbance, a non-replicable dynamic identifier is generated, and replay attacks and signal tampering are effectively defended; through triple weight adjustment of hop count attenuation, signal-to-noise compensation and time delay deduction, vehicle position change and link fluctuation are automatically adapted, and the synchronization failure risk in scenes such as a tunnel is eliminated; a safety degradation mechanism is introduced, control instruction transmission is prohibited when abnormity occurs, basic communication is maintained in combination with a pre-stored key, and vehicle misoperation caused by key synchronization failure is prevented.
Owner:CHINA VAGON AUTOMOTIVES HLDG CO LTD

Quantum key distribution method and device, electronic equipment and computer storage medium

The embodiment of the invention provides a quantum key distribution method and device, electronic equipment and a computer readable storage medium, and relates to the technical field of quantum key distribution, and the method comprises the steps that a quantum key distribution network control center responds to a quantum key distribution request, obtains the network state information of a quantum key distribution network, and sends the network state information to a server; the method comprises the steps of receiving network state information, determining a path set for distributing quantum keys based on the network state information, then determining a path weight of each reachable path based on the network state information, determining a distribution mode of the quantum keys based on the path weights, and determining a target path from the path set; and sending the distribution mode and the target path to a source node. According to the embodiment of the invention, the network state can be sensed in real time, the routing strategy can be adjusted, the problem of quantum link quality fluctuation or node resource shortage can be effectively solved, quantitative analysis of path security efficiency and resource efficiency is realized, and the robustness and flexibility of the system are improved.
Owner:中电信量子信息科技集团有限公司

Quantum key distribution network situation assessment method, device, equipment and medium

The embodiment of the invention provides a quantum key distribution network situation assessment method and device, equipment and a medium. The method comprises the following steps: acquiring performance data of a quantum key distribution network; the performance data comprises network structure data, key performance data, communication quality data, data transmission data and an evaluation model; determining a comprehensive influence factor according to the performance data; the comprehensive influence factor is used for reflecting the importance degree of the performance data to the quantum key distribution network situation; and according to the performance data, the comprehensive influence factor and the evaluation model, determining the situation of the target quantum key distribution network, thereby significantly improving the security and reliability of the QKD network. Potential security vulnerabilities and attack risks can be found and coped with in time through evaluation of the network situation, and the security and high efficiency of the key distribution process are ensured.
Owner:中电信量子信息科技集团有限公司 +1

Key injection method and system and computer equipment

The invention relates to a key injection method and system and computer equipment. The method comprises the following steps: sending a key request to a key basic system, so that the key basic system requests a quantum key from a quantum key distribution system, and obtains the quantum key generated by the quantum key distribution system; obtaining a quantum key generated by a quantum key distribution system; acquiring encryption key information transmitted by the key basic system; the encryption key information is obtained by encrypting the controller key by the key basic system according to the quantum key; and decrypting the encrypted key information through the quantum key to obtain a controller key, and injecting the controller key into the target controller. The quantum key generated by the quantum key distribution system has the characteristic of quantum attack resistance. In the controller key transmission process, the controller key is encrypted through the quantum key, so that the safety of the controller key is further improved, and the controller key is prevented from being leaked.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Method and system for verifying a cryptographic key forwarding path in a quantum key distribution network

The invention provides a method for verifying a key forwarding path of at least one cryptographic key in a quantum key distribution, QKD, network, and a system for the verification of the key forwarding path of at least one cryptographic key, the method comprising at least steps of:selecting (using either a centralized or a decentralized method) a number of QKD nodes of the QKD network, which define a key forwarding path of the at least one cryptographic key;transmitting to each of the selected QKD nodes data indicating at least partial information about the key forwarding path of the at least one cryptographic key;generating, by each selected QKD node, a digital signature, wherein the digital signature contains at least the data indicating at least partial information about the key forwarding path of the at least one cryptographic key;transmitting, by each selected QKD node (N1-N9), the digital signature generated at that selected QKD node (N1-N9); andverifying the key forwarding path of the at least one cryptographic key through a verification of the transmitted digital signatures.
Owner:ADVA NETWORK SECURITY GMBH

Clinical nursing patient information monitoring and recording method and system

According to the clinical nursing patient information monitoring and inputting method and system, the data accuracy, the data inputting efficiency and the privacy protection safety are improved; the method comprises the following steps: firstly, collecting and preprocessing vital sign data of a patient in real time through various physiological sensors; then, acquiring a nursing record image, acquiring nursing record data through an OCR model, acquiring nursing information voice, transwriting the nursing record data and the nursing information voice into nursing information data through a medical scene voice transwriting model, and performing unified standardization processing on the three groups of data to generate patient information data; and finally, when patient information data is input, symmetric encryption is carried out by adopting a national cryptographic SM4 algorithm, encrypted data is obtained, a dynamic encryption key is generated through an ECDH key distribution technology, and the dynamic encryption key can be called to carry out decryption operation after authentication of a dual protection mechanism of Hash value pre-verification and identity authentication is passed.
Owner:DUHUI HEALTH (CHENGDU) MEDICAL TECH CO LTD

Key exchange system, hub apparatus, QKD apparatus, method, and program

A key exchange system according to an aspect of the present disclosure includes: a plurality of quantum key distribution (QKD) apparatuses that executes a quantum key distribution protocol including at least error correction; and a plurality of hub apparatuses that performs encrypted communication with each other, in which each of the hub apparatuses includes a key generation unit configured to generate an encryption key for performing the encrypted communication with another hub apparatus based on information received from a corresponding one of the QKD apparatuses, and each of the QKD apparatuses includes a QKD processing unit configured to execute the quantum key distribution protocol with another QKD apparatus and generate a correction key from a ciphertext of random number information, and a first transmission unit configured to transmit information representing a result of basis reconciliation in the quantum key distribution protocol to a corresponding one of the hub apparatuses.
Owner:NT T INC

Discrete variable quantum key distribution data coordination method

The invention belongs to the technical field of quantum communication, and particularly relates to a discrete variable quantum key distribution data coordination method and system based on a code rate adaptive multi-system LDPC code. Aiming at the defect of performance bottleneck of an existing discrete variable quantum key distribution system adopting a binary low-density parity check code in a long-distance and high-noise environment, the invention provides a discrete variable quantum key distribution data coordination method. The method comprises the following steps: preparing and transmitting a quantum state; screening data; error rate estimation and eavesdropping detection; data coordination based on symbol-level code rate adaptation and / or bit-level code rate adaptation; and confidentiality enhancement. According to the method disclosed by the invention, the construction and storage pressure of the system on error correction codes with different code rates is obviously reduced, the robustness of the system under a complex channel condition is enhanced, and efficient and unconditionally safe key distribution is ensured; the eavesdropping attack can be effectively resisted, and the communication security is ensured.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY +3

Security gateway setting method and device based on quantum encryption

The invention relates to a security gateway setting method and device based on quantum encryption, the method is applied to a data encryption process between a local security gateway and an opposite-end security gateway, and the security gateway setting method based on quantum encryption comprises the following steps: responding to an encryption request of the local security gateway; generating a dynamic key pair through a quantum key distribution system, and establishing an index relationship between the encryption request and the dynamic key pair; after it is determined that the opposite-end security gateway receives the quantum encryption data, a decryption permission submitted by a gateway verification service server is received, the decryption permission is obtained after the relation value of the index relation is released, and meanwhile the encryption value in the index relation is destroyed; and decrypting the quantum encrypted data at the opposite-end security gateway, and isolating and storing the decrypted data in a quantum security storage area independent of the local security gateway and the opposite-end security gateway. According to the invention, the security of end-to-end data transmission is improved.
Owner:NORDSON QIKE (QINGDAO) INFORMATION TECHNOLOGY CO LTD

Encryption Key Distribution System

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key connector service is used to coordinate communications with a key management server for generating plaintext keys for data encryption and encrypted keys based on the plain text keys, and with a key broker server for storing and retrieving copies of the encrypted keys. A context identifier may be associated with an encrypted key and used to track which data has been encrypted with an underlying plaintext key. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.
Owner:ZOOM COMMUNICATIONS INC

Anti-frequency analysis searchable encryption method and system

According to the anti-frequency analysis searchable encryption method and system, a certificateless encryption system is introduced, for a scene with limited computing resources, the scheme is ensured to be safe and suitable for the scene with the limited computing resources, meanwhile, a trap door algorithm is designed based on a probability trap door generation algorithm, and the security of the scheme is improved. The method improves the resistance of a system to frequency analysis attacks, solves the problem of secret key trusteeship due to the fact that identity information and secret key distribution are concentrated in a private key generation center in a traditional encryption scheme, and improves the encryption efficiency. The technical problem that malicious users are easy to obtain the privacy information of the target keyword by performing frequency analysis on trap doors and initiating keyword guessing attacks is solved.
Owner:GUIZHOU UNIV

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Securely recording and retrieving encrypted video conferences

One disclosed example method includes obtaining a meeting cryptographic key; transmitting, from a client device to a video conference provider, a request to initiate an encrypted video conference, the encrypted video conference including a plurality of participants; distributing the meeting cryptographic key to each participant of the plurality of participants; obtaining a public cryptographic key of a key pair, the key pair including the public cryptographic key and a private cryptographic key; encrypting the meeting cryptographic key using the public cryptographic key; transmitting, from the client device to the video conference provider, a request to record the video conference; encrypting audio and video from a microphone and image sensor of the client device using the meeting cryptographic key; transmitting the encrypted audio and video to the video conference provider; and providing the encrypted meeting cryptographic key to the video conference provider.
Owner:ZOOM COMMUNICATIONS INC