Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Key distribution center" patented technology

In cryptography, a key distribution center (KDC) is part of a cryptosystem intended to reduce the risks inherent in exchanging keys. KDCs often operate in systems within which some users may have permission to use certain services at some times and not at others.

Anti-Byzantine privacy protection federal learning method and system based on block chain

The invention discloses an anti-Byzantine privacy protection federated learning method and system based on a block chain. The anti-Byzantine privacy protection federated learning method is realized through the federated learning system comprising a key distribution center, a plurality of clients, two non-collusion servers and a block chain network. According to the method, the data privacy of a client side is guaranteed through a safety calculation process of cooperation of double servers, attacks caused by malicious client sides are reduced as much as possible through a self-adaptive clustering and robustness aggregation method, and reputation values of the client sides are managed through intelligent contracts. The reputation value is used to set the award and penalty obtained after the client participates in federal learning, and the blockchain increases transparency and reliability for the system. And updating the global model based on a security calculation process under a non-collusion double-server architecture, and finally obtaining a safe and reliable global model after training is finished.
Owner:HANGZHOU NORMAL UNIVERSITY

Method for key replenishment for quantum local area networks

The application discloses a key filling method for a quantum local area network, the quantum local area network comprising a first control station, a quantum key filling machine and a key distribution center, the first control station and the quantum key filling machine being in communication connection, and the method comprising: the quantum key filling machine sending a key filling request to the first control station. The first control station determines a target distribution strategy from preset distribution strategies according to the type of the key filling request, the preset distribution strategies comprising a first preset key distribution strategy and a second preset key distribution strategy. The first control station distributes the obtained quantum symmetric key to the quantum key filling machine and / or the key distribution center according to the target distribution strategy to perform key filling, wherein the quantum symmetric key distributed based on the first preset key distribution strategy is a directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is a local area network key. Thus, the problem that the quantum key is single and cannot provide diversified services is solved.
Owner:中电信量子信息科技集团有限公司

SecOC vehicle-mounted safety communication method based on dynamic key management enhancement

The invention discloses a SecOC vehicle-mounted safety communication method based on dynamic key management enhancement, which realizes on-demand distribution, dynamic updating and full life cycle management of SecOC keys by introducing a key distribution center. The ECU negotiates a unique preset key through the KDC client and the KDC server; the KDC client requests a service bill from the KDC server based on the service identifier of the application; the SecOC key is dynamically distributed by the KDC, and automatic rotation based on a time strategy and emergency update based on a security event are supported. The SecOC message adopts a gPTP timestamp as a freshness value, and after the data unit and the freshness value are spliced, a message authentication code is calculated. According to the invention, the secret key is not statically preset any more, but is dynamically distributed by the KDC and supports online updating, and through combination of bidirectional certificate authentication and timestamp double-factor authentication, full-life-cycle safety management of the vehicle service secret key is realized, and the risk of secret key leakage is effectively coped with.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Secure communication method, key distribution center, device, medium, and product

The application discloses a secure communication method, which comprises the following steps: a terminal device sends a session key request message; a key distribution center receives the session key request message, determines to obtain a key between a second quantum key distribution node and a first quantum key distribution node based on the session key request message, and sends session information to a server; the server receives the session information, and sends a key request message to the first quantum key distribution node; the first quantum key distribution node receives the key request message, obtains a session key, and sends the session key to the server; the session key is used for the server and the terminal device to perform secure communication; and the server receives the session key, and sends the session key to the terminal device. The application also discloses a server, a key distribution center, a terminal device, a key update terminal device, a first quantum key distribution node, a computer readable storage medium and a computer program product.
Owner:CHINA MOBILE COMM LTD RES INST +1

A method, apparatus, medium, and electronic device for authentication

ActiveCN115879089BTicketInternet privacy
This application provides an authentication method, apparatus, medium, and electronic device. The method includes: after a client obtains a first ticket through a first key distribution center and first user identity information, obtaining second user identity information corresponding to the first user identity information; obtaining a second ticket from a second key distribution center through the second user identity information; and providing the second ticket to a server, so that the server determines whether it can receive a database access request from the client based on the second ticket. This application provides a dual-KDC authentication method that hides actual user information, thus preventing user information leakage.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Extended quantum key distribution network and method for scalable initial authentication key distribution between entities

PCT designated stageWO2025223723A1Key distribution for secure communicationSecure communicationOrganizational security
An extended Quantum Key Distribution (QKD) network for scalable initial authentication key distribution between entities in the extended QKD network is provided. The extended QKD network comprising at least a first entity, a second entity, and a central Key Distribution Center (KDC). The KDC is configured to: obtain, using organizational security measures, a secret key between the KDC and the first entity, K(KDC,A); obtain, using organizational security measures, a secret key between the KDC and the second entity, K(KDC,B); and receive, from the first entity using information theoretically secure (ITS) communication, a request for starting the initial authentication key distribution between the first entity and the second entity.
Owner:HUAWEI TECH DUESSELDORF

Cross-KDC key management method and device, electronic equipment and readable storage medium

The invention provides a cross-KDC key management method and device, electronic equipment and a readable storage medium, and relates to the technical field of information security, and the method comprises the steps: selecting any key distribution center as a key generation center for generating a key; in response to a key acquisition request initiated by an application program of a to-be-acquired key, matching a key sending rule based on an attribute judgment result of whether a key distribution center connected with the application program of the to-be-acquired key is a key generation center or not, and sending the key to the application program of the to-be-acquired key according to the matched key sending rule; sending the latest key generated by the key generation center to the same application program of the to-be-acquired key located in different key distribution centers; and after determining that each application program of the to-be-acquired key successfully acquires the latest key, executing key starting instruction broadcasting, so that the same application program in each key distribution center synchronously starts the latest key. The purpose of key distribution and starting consistency control in the multi-KDC environment is achieved.
Owner:CHINA CONSTRUCTION BANK +1

Identity authentication method and system, electronic device, storage medium and program product

The application discloses an identity authentication method and system, an electronic device, a storage medium and a program product, relates to the technical field of security, and only when a legal user is determined for the first time, a key distribution center knows a real name corresponding to a client, a signature, a ticket authorization ticket generation process and a subsequent anonymous access process of a corresponding server are all initiated by the client in a pseudonym, therefore, the key distribution center and the corresponding server do not know the association between the pseudonym and the client, so that the user privacy is protected.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Key transfer method, apparatus, device, system, storage medium and program product

PendingCN122179083AKey distribution for secure communicationKey distribution centerSession key
The application discloses a key transfer method, device, equipment, system, storage medium and program product, relates to the technical field of communication, and provides a safe key service for a mobile terminal. The method comprises the following steps: a session key request is sent to a key distribution center, the session key request is used for requesting a session key, the session key is used for communication between the mobile terminal and a server; and the session key sent by the key distribution center is received, the session key is obtained by the key distribution center from a first QKD node connected with the key distribution center, and the session key is generated by negotiation of the first QKD node and a second QKD node connected with the server. The embodiment of the application can provide a safe key service for a mobile terminal.
Owner:CHINA MOBILE COMM LTD RES INST +1

Federal learning anti-poisoning attack method based on homomorphic encryption

The invention discloses a federal learning anti-poisoning attack method based on homomorphic encryption, which comprises the following steps of: generating a homomorphic encryption key pair through a key distribution center, distributing a public key, and processing a local data set by a client by utilizing a self-adaptive truncation singular value technology based on meta-learning; training a local data set and calculating a gradient; and then, the client uploads the local gradient subjected to homomorphic encryption to a server. And the server dynamically adjusts the detection intensity of the current round according to the success rate of the poisoning attack of the previous round, scores the clients marked as malicious gradients through a three-stage malicious gradient detection mechanism, and judges the gradients of which the reputation scores are lower than a predetermined threshold value as malicious gradients and eliminates the malicious gradients. In the gradient aggregation process, weighted aggregation is carried out according to the reputation score. According to the method, wide experiments are carried out, the result shows that the model can effectively detect the malicious encryption gradient, and the model is proved to be superior to other existing methods through wide analysis and comparison.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

A Cloud-Based Certificate-Free Cross-Domain Authentication Method

This invention discloses a certificate-free cross-domain authentication method in the cloud, comprising deploying key distribution centers in both the CLC domain and the trusted domain and generating system parameters; the user and the cloud service provider (CSP) each applying for partial private keys and combining them with secret values ​​to generate public-key and private-key pairs; the user calculating authentication information and sending an encrypted request; the CSP verifying the user's legitimacy and returning an encrypted response upon successful verification; the user receiving the response message, verifying the synchronized valid sequence number and the CSP; upon successful verification, saving the legitimate provider information, receiving cloud service resources, and establishing a cross-domain trust relationship and session negotiation key. This invention constructs a certificate-free cross-domain authentication method that abandons the complex certificate chain management of traditional PKI; it adopts a signature and signcryption-based primitive, balancing data confidentiality, integrity, and low computational complexity; and through session key negotiation and a local legitimate user list caching mechanism, it avoids duplicate authentication and improves processing efficiency.
Owner:GUANGDONG UNIV OF SCI & TECH

Train-to-ground communication method and apparatus, and device and storage medium

Disclosed in the present invention are a train-to-ground communication method and apparatus, and a device and a storage medium. The method comprises: acquiring a preset master key and operation-related information of a train, and determining a working key on the basis of the preset master key and the operation-related information; encrypting the working key by means of the preset master key so as to generate working-key ciphertext, and sending the working-key ciphertext to a ground device, so as to acquire, on the basis of the working-key ciphertext, a confirmation message sent by the ground device, and generating a consistency check result on the basis of the confirmation message; and when the consistency check result indicates that the check is successful, communicating with the ground device by means of the working key. A key distribution center is established on the basis of train-to-ground wireless communication, so as to realize key management of the train-to-ground wireless communication; a train acquires a session key from the key distribution center on the basis of operation-related information, and uses the session key to perform encrypted communication; and when the session key is not acquired, a standby key is used for encrypted communication, thereby improving the communication reliability, and ensuring the operation safety of the train.
Owner:CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD

Secure communication method, key distribution center, device, medium, and product

The application discloses a secure communication method, which comprises the following steps: a terminal device sends a session key request message to a key distribution center; the key distribution center receives the session key request message, and determines to obtain a key between a first quantum key distribution node and a second quantum key distribution node based on the session key request message; the key distribution center sends a key request message to a third quantum key distribution node; the third quantum key distribution node performs a key generation process between the first quantum key distribution node and the second quantum key distribution node, obtains a session key, and sends the session key to the key distribution center; and the key distribution center receives the session key, and sends the session key to the terminal device and a server. The application also discloses a key distribution center, a terminal device, a server, a key updating terminal device, a third quantum key distribution node, a computer readable storage medium and a computer program product.
Owner:CHINA MOBILE COMM LTD RES INST +1

Key charging method and authentication method for quantum local area network

The invention discloses a key charging method and an authentication method for a quantum local area network. The quantum local area network comprises a quantum key charging machine, a first centralized control station, a first target key distribution center and a second target key distribution center, and the method comprises the steps that the quantum key charging machine sends a key charging request to the first centralized control station, and the key charging request comprises a first key charging request. And under the condition that the key charging request is a first key charging request, the first centralized control station sends a first quantum key in the generated cross-domain authentication key to a second target key distribution center. The second target key distribution center stores the first quantum key. And the first centralized control station sends a second quantum key in the cross-domain authentication key and the cross-domain authentication identification information to the quantum key charging machine. And the quantum key charging machine performs charging processing on the terminal key storage medium according to the second quantum key and the cross-domain authentication identification information. In this way, the preset correspondence of the cross-domain key is realized, so that the cross-domain authentication process is simplified.
Owner:中电信量子信息科技集团有限公司

Enterprise internal cross-system authentication processing method, system, equipment and medium

The invention discloses an enterprise internal cross-system authentication processing method and system, equipment and a medium, and the method specifically comprises the steps: generating a differential asymmetric encryption key for a system pair with a bidirectional authentication edge in an enterprise through a key distribution center based on the node security level of a system authentication relation graph; when a cross-system access request is detected, generating a temporary token carrying a fine-grained permission tag and failure time according to the differentiated asymmetric encryption key; based on the temporary token, extracting a historical behavior sequence of the associated edge through an anomaly detection model, and when an abnormal mode is detected, triggering permission recovery and freezing the temporary token; and for the temporary token which is not frozen, creating a default role with a time limit for the unregistered user through the target system. According to the invention, safe and flexible enterprise internal cross-system authentication processing with self-adaptive capability is realized, and the safety and system performance of cross-system authentication are effectively guaranteed.
Owner:ANHUI SANQI JIYU NETWORK TECH CO LTD

Authentication methods, related equipment, storage media, and computer program products

ActiveCN118802131BKey distribution for secure communicationSoftware engineeringKey distribution center
This application discloses an authentication method, apparatus, first node, key distribution center (KDC), second node, first server, second server, storage medium, and computer program product. The method includes: the first node sending first information to the KDC, the first information requesting service authorization for N service nodes in a first domain; receiving second information sent by the KDC, the second information indicating authorization completion, the second information including a first key and third information, the first key including a session key between the first domain as a first client and a first server, the third information representing authorized access credentials associated with the client and the first server; and sending the first key and the third information to the other N service nodes besides the first node, the third information being used at least for service authentication between the service nodes and the first server.
Owner:CHINA MOBILE COMM LTD RES INST +1

Data communication system, center device, master device, and storage medium storing secret information exchange program

A data communication system includes a center device that distributes update data to a master device, and a master device that installs the update data in an electronic control unit to be reprogrammed. The center device and the master device exchange random secret information using an algorithm of a Diffie-Hellman key exchange (DHE) or an Elliptic curve Diffie-Hellman key exchange (ECDHE) for key distribution. The center device encrypts an encryption key for encrypting update data based on the exchanged secret information, stores the encrypted encryption key in a campaign notification, places the update data encrypted with the encryption key in a content delivery network, and transmits the campaign notification storing the encrypted encryption key to a vehicle system.
Owner:DENSO CORP

User privacy protection method based on privacy enhancement federated learning

The invention belongs to the technical field of privacy protection, and relates to a user privacy protection method based on privacy enhanced federated learning, which comprises the following steps that: a secret key distribution center generates a public key and a private key and respectively distributes the public key and the private key to participants and a central server; the central server initializes model parameters and transmits the model parameters to all participants, each participant trains a model on a local data set and encrypts the local gradient after calculating a loss function and the local gradient, the central server receives the encryption gradients of all participants, and the encryption gradients are aggregated and decrypted to obtain a global gradient; the participants receive the global gradient and update the local model parameters, and each participant can flexibly select and adjust the implementation mode of each module according to the own data characteristics and business requirements to adapt to different data types and sources, so that the problem of insufficient flexibility in the traditional method is solved.
Owner:QINGDAO SONLI SOFTWARE INFORMATION TECH

Dynamic searchable encryption method, decryption method, encryption device and decryption device

The application discloses a dynamic searchable encryption method, a decryption method, an encryption device and a decryption device. H 2When updating data, the key distribution center sends system public parameters and keys to a data owner, the data owner uses an anti-collision hash function 2to generate a deduplication verification tag to determine whether a file already exists; a one-time private key generated by using other hash functions is used to encrypt an index, an update token, ciphertext shielding a previous token, encrypted index, encrypted file identifier and file ciphertext are updated to a cloud database, and encrypted database updating is realized.Searching data, the key distribution center sends system public parameters and keys to a data user; after a cloud server receives a search request initiated by the data user, the cloud server searches and matches out results and returns the data user; the user decrypts to obtain plaintext files, and searching of the encrypted database is realized.The application can realize data deduplication and connection keyword search functions while guaranteeing dynamic searchable security.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Secoc vehicle safety communication method based on dynamic key management enhancement

The application discloses a kind of SecOC vehicle-mounted safety communication methods based on dynamic key management enhancement, by introducing key distribution center, the on-demand distribution of SecOC key, dynamic update and whole life cycle management are realized.ECU is negotiated by KDC client and KDC server Unique preset key;KDC client requests service ticket based on the service identification of application to KDC server;SecOC key is dynamically assigned by KDC, supports automatic rotation based on time strategy and emergency update based on security event.SecOC message uses gPTP timestamp as freshness value, after data unit and freshness value are spliced, message authentication code is calculated.In the application, key is no longer static preset, but is dynamically distributed by KDC and supports online update, combined with two-way certificate authentication and timestamp two-factor authentication, realize the whole life cycle safety management of vehicle service key, effectively deal with key leakage risk.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

A fingerprint activity detection method based on CKKS homomorphic encryption

The application provides a fingerprint activity detection method based on CKKS homomorphic encryption, comprising the following steps: step 1, establishing a three-party interaction system model composed of a user end, a key distribution center and a cloud server; step 2, after completing identity verification, the user end encrypts the image using a public key, and transmits the ciphertext image to the cloud server through a public channel; step 3, after receiving the ciphertext image, the cloud server uses a second deep learning model to identify the ciphertext image and obtains a ciphertext result; the cloud server transmits the ciphertext result to the user end through the public channel, and the user end uses the private key held to decrypt, and finally obtains the fingerprint activity detection result. The method can accurately and effectively distinguish the activity of the fingerprint without exposing the input fingerprint image information. The core goal of adding the homomorphic encryption technology is to ensure the privacy of the fingerprint data, and effectively distinguish the cheating attacks initiated by the living body fingerprint and the fake fingerprint.
Owner:NANJING UNIV OF INFORMATION SCI & TECH +1

Registration attribute retrieval encryption method based on cloud edge collaboration

The invention provides a registration attribute retrieval encryption method based on cloud edge collaboration, and belongs to the technical field of decentralized attribute-based encryption and searchable encryption. The technical problem that an existing retrieval encryption method based on attributes depends on a single-point fault of a trusted key distribution center is solved. According to the technical scheme, the method comprises the following steps that S10, a system is initialized; s20, the data applicant generates public and private keys; s30, verifying the legality of the public key; s40, aggregating user attributes and public keys; s50, encrypting the data to be shared and the keywords; s60, retrieving the shared ciphertext matched with the keyword; and S70, the data applicant decrypts the authorized ciphertext. A retrieval encryption mechanism based on registration attributes is constructed, the problem that an existing retrieval encryption method based on attributes depends on a single-point fault of a trusted key distribution center is avoided, fine-grained authorization of shared data and fine-grained retrieval in a ciphertext state are achieved on the premise that privacy of retrieval keywords is protected, and decryption efficiency is improved.
Owner:NANTONG UNIV

Blockchain-based smart grid data security sharing and quality evaluation method

PendingCN122333436AContent IdentifierData set
This invention discloses a blockchain-based method for secure data sharing and quality assessment in smart grids, belonging to the field of data security sharing technology. The method includes: system initialization and user registration, where a key distribution center distributes keys and blockchain addresses to data owners, researchers, and a quality assessment platform; data collection and uploading, where data owners encrypt datasets, generate content identifiers in blocks, store them in IPFS, and upload the stored information to the blockchain to form trusted evidence; smart contracts and access control, setting access policies and issuing access tokens to verified researchers to obtain the dataset; dataset quality assessment, generating and providing feedback on a quality report by combining label reordering, correlation coefficient testing, and performance evaluation testing; and a reward mechanism, allocating reputation values ​​and rewards to data owners based on dataset quality. This invention achieves secure and trusted data sharing and scientific quality assessment, promoting the continuous provision of high-quality data.
Owner:NANJING UNIV OF POSTS & TELECOMM

Multi-receiver bilateral access control privacy protection cross-domain data sharing method

The invention discloses a multi-receiver bilateral access control privacy protection cross-domain data sharing method. The method comprises the following steps: executing system parameter initialization by a total trusted center and generating a master key; generating respective key pairs for the trusted center, the key distribution center and the vehicle based on the master key and the public parameters; the sender vehicle generates a common original encrypted ciphertext for the target receiver vehicle set by using the private key of the sender vehicle and the public key of the receiver; the receiver vehicle decrypts the ciphertext by using the private key of the receiver vehicle and the public key of the sender; and in a cross-domain sharing scene, the road side unit safely converts the original ciphertext into a re-encrypted ciphertext through the re-encrypted key, so that a target domain receiver can decrypt the re-encrypted ciphertext. According to the method, fine-grained bilateral access control and privacy protection in a cross-domain environment are realized, on the premise of ensuring data security, the calculation and communication overhead of one-to-many encryption is remarkably reduced, complex certificate management is avoided, and the efficiency and practicability of Internet of Vehicles data sharing are improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Key charging method for quantum local area network

ActiveCN121283618AKey distribution for secure communicationTelecommunicationsKey distribution center
The invention discloses a secret key charging method for a quantum local area network, the quantum local area network comprises a first centralized control station, a quantum secret key charging machine and a secret key distribution center, the first centralized control station and the quantum secret key charging machine establish communication connection, and the method comprises the following steps: the quantum secret key charging machine sends a secret key charging request to the first centralized control station; the first centralized control station determines a target distribution strategy from preset distribution strategies according to the type of the key charging request, and the preset distribution strategies comprise a first preset key distribution strategy and a second preset key distribution strategy; the first centralized control station distributes the obtained quantum symmetric key to a quantum key charging machine and / or a key distribution center according to a target distribution strategy so as to perform key charging, the quantum symmetric key distributed based on a first preset key distribution strategy is a directional key, and the quantum symmetric key distributed based on a second preset key distribution strategy is a directional key. The quantum symmetric key distributed based on the second preset key distribution strategy is the local area network key. Therefore, the problems that the quantum key is single and diversified services cannot be provided are solved.
Owner:中电信量子信息科技集团有限公司

Data sharing method and system based on anti-quantum attribute-based encryption and secret sharing

The invention relates to the technical field of information security, in particular to a data sharing method and system based on anti-quantum attribute-based encryption and secret sharing, and the method comprises the steps that a key distribution center generates a symmetric key, a main public key, a main private key, a certificate and an anti-quantum private key of a user; the database adopts a symmetric key to encrypt different service data into a ciphertext, and adopts an anti-quantum attribute-based encryption algorithm to encrypt the symmetric key to generate an intermediate ciphertext; the database splits the intermediate ciphertext into n shares through a secret sharing technology and signs the shares; when service terminals not less than t threshold values submit access requests and the access requests are verified by an authorization mechanism, calling corresponding secret shares and ciphertexts in the database and sending the secret shares and ciphertexts to the service terminals; all the successfully verified service terminals recover the intermediate ciphertext through secret reconstruction, the symmetric key is obtained through decryption by using the anti-quantum private key, the ciphertext is decrypted by using the decrypted symmetric key, and the service data is recovered. The sharing security of the service sensitive data can be improved.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1