Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Key distribution center" patented technology

In cryptography, a key distribution center (KDC) is part of a cryptosystem intended to reduce the risks inherent in exchanging keys. KDCs often operate in systems within which some users may have permission to use certain services at some times and not at others.

Method for key replenishment for quantum local area networks

The application discloses a key filling method for a quantum local area network, the quantum local area network comprising a first control station, a quantum key filling machine and a key distribution center, the first control station and the quantum key filling machine being in communication connection, and the method comprising: the quantum key filling machine sending a key filling request to the first control station. The first control station determines a target distribution strategy from preset distribution strategies according to the type of the key filling request, the preset distribution strategies comprising a first preset key distribution strategy and a second preset key distribution strategy. The first control station distributes the obtained quantum symmetric key to the quantum key filling machine and / or the key distribution center according to the target distribution strategy to perform key filling, wherein the quantum symmetric key distributed based on the first preset key distribution strategy is a directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is a local area network key. Thus, the problem that the quantum key is single and cannot provide diversified services is solved.
Owner:中电信量子信息科技集团有限公司

A method, apparatus, medium, and electronic device for authentication

ActiveCN115879089BTicketInternet privacy
This application provides an authentication method, apparatus, medium, and electronic device. The method includes: after a client obtains a first ticket through a first key distribution center and first user identity information, obtaining second user identity information corresponding to the first user identity information; obtaining a second ticket from a second key distribution center through the second user identity information; and providing the second ticket to a server, so that the server determines whether it can receive a database access request from the client based on the second ticket. This application provides a dual-KDC authentication method that hides actual user information, thus preventing user information leakage.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Cross-KDC key management method and device, electronic equipment and readable storage medium

The invention provides a cross-KDC key management method and device, electronic equipment and a readable storage medium, and relates to the technical field of information security, and the method comprises the steps: selecting any key distribution center as a key generation center for generating a key; in response to a key acquisition request initiated by an application program of a to-be-acquired key, matching a key sending rule based on an attribute judgment result of whether a key distribution center connected with the application program of the to-be-acquired key is a key generation center or not, and sending the key to the application program of the to-be-acquired key according to the matched key sending rule; sending the latest key generated by the key generation center to the same application program of the to-be-acquired key located in different key distribution centers; and after determining that each application program of the to-be-acquired key successfully acquires the latest key, executing key starting instruction broadcasting, so that the same application program in each key distribution center synchronously starts the latest key. The purpose of key distribution and starting consistency control in the multi-KDC environment is achieved.
Owner:CHINA CONSTRUCTION BANK +1

Key transfer method, apparatus, device, system, storage medium and program product

PendingCN122179083AKey distribution for secure communicationKey distribution centerSession key
The application discloses a key transfer method, device, equipment, system, storage medium and program product, relates to the technical field of communication, and provides a safe key service for a mobile terminal. The method comprises the following steps: a session key request is sent to a key distribution center, the session key request is used for requesting a session key, the session key is used for communication between the mobile terminal and a server; and the session key sent by the key distribution center is received, the session key is obtained by the key distribution center from a first QKD node connected with the key distribution center, and the session key is generated by negotiation of the first QKD node and a second QKD node connected with the server. The embodiment of the application can provide a safe key service for a mobile terminal.
Owner:CHINA MOBILE COMM LTD RES INST +1

Federal learning anti-poisoning attack method based on homomorphic encryption

The invention discloses a federal learning anti-poisoning attack method based on homomorphic encryption, which comprises the following steps of: generating a homomorphic encryption key pair through a key distribution center, distributing a public key, and processing a local data set by a client by utilizing a self-adaptive truncation singular value technology based on meta-learning; training a local data set and calculating a gradient; and then, the client uploads the local gradient subjected to homomorphic encryption to a server. And the server dynamically adjusts the detection intensity of the current round according to the success rate of the poisoning attack of the previous round, scores the clients marked as malicious gradients through a three-stage malicious gradient detection mechanism, and judges the gradients of which the reputation scores are lower than a predetermined threshold value as malicious gradients and eliminates the malicious gradients. In the gradient aggregation process, weighted aggregation is carried out according to the reputation score. According to the method, wide experiments are carried out, the result shows that the model can effectively detect the malicious encryption gradient, and the model is proved to be superior to other existing methods through wide analysis and comparison.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

A Cloud-Based Certificate-Free Cross-Domain Authentication Method

PendingCN122339678AComputation complexityCertificate
This invention discloses a certificate-free cross-domain authentication method in the cloud, comprising deploying key distribution centers in both the CLC domain and the trusted domain and generating system parameters; the user and the cloud service provider (CSP) each applying for partial private keys and combining them with secret values ​​to generate public-key and private-key pairs; the user calculating authentication information and sending an encrypted request; the CSP verifying the user's legitimacy and returning an encrypted response upon successful verification; the user receiving the response message, verifying the synchronized valid sequence number and the CSP; upon successful verification, saving the legitimate provider information, receiving cloud service resources, and establishing a cross-domain trust relationship and session negotiation key. This invention constructs a certificate-free cross-domain authentication method that abandons the complex certificate chain management of traditional PKI; it adopts a signature and signcryption-based primitive, balancing data confidentiality, integrity, and low computational complexity; and through session key negotiation and a local legitimate user list caching mechanism, it avoids duplicate authentication and improves processing efficiency.
Owner:GUANGDONG UNIV OF SCI & TECH

Data communication system, center device, master device, and storage medium storing secret information exchange program

A data communication system includes a center device that distributes update data to a master device, and a master device that installs the update data in an electronic control unit to be reprogrammed. The center device and the master device exchange random secret information using an algorithm of a Diffie-Hellman key exchange (DHE) or an Elliptic curve Diffie-Hellman key exchange (ECDHE) for key distribution. The center device encrypts an encryption key for encrypting update data based on the exchanged secret information, stores the encrypted encryption key in a campaign notification, places the update data encrypted with the encryption key in a content delivery network, and transmits the campaign notification storing the encrypted encryption key to a vehicle system.
Owner:DENSO CORP

Dynamic searchable encryption method, decryption method, encryption device and decryption device

The application discloses a dynamic searchable encryption method, a decryption method, an encryption device and a decryption device. H 2When updating data, the key distribution center sends system public parameters and keys to a data owner, the data owner uses an anti-collision hash function 2to generate a deduplication verification tag to determine whether a file already exists; a one-time private key generated by using other hash functions is used to encrypt an index, an update token, ciphertext shielding a previous token, encrypted index, encrypted file identifier and file ciphertext are updated to a cloud database, and encrypted database updating is realized.Searching data, the key distribution center sends system public parameters and keys to a data user; after a cloud server receives a search request initiated by the data user, the cloud server searches and matches out results and returns the data user; the user decrypts to obtain plaintext files, and searching of the encrypted database is realized.The application can realize data deduplication and connection keyword search functions while guaranteeing dynamic searchable security.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Secoc vehicle safety communication method based on dynamic key management enhancement

The application discloses a kind of SecOC vehicle-mounted safety communication methods based on dynamic key management enhancement, by introducing key distribution center, the on-demand distribution of SecOC key, dynamic update and whole life cycle management are realized.ECU is negotiated by KDC client and KDC server Unique preset key;KDC client requests service ticket based on the service identification of application to KDC server;SecOC key is dynamically assigned by KDC, supports automatic rotation based on time strategy and emergency update based on security event.SecOC message uses gPTP timestamp as freshness value, after data unit and freshness value are spliced, message authentication code is calculated.In the application, key is no longer static preset, but is dynamically distributed by KDC and supports online update, combined with two-way certificate authentication and timestamp two-factor authentication, realize the whole life cycle safety management of vehicle service key, effectively deal with key leakage risk.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Registration attribute retrieval encryption method based on cloud edge collaboration

The invention provides a registration attribute retrieval encryption method based on cloud edge collaboration, and belongs to the technical field of decentralized attribute-based encryption and searchable encryption. The technical problem that an existing retrieval encryption method based on attributes depends on a single-point fault of a trusted key distribution center is solved. According to the technical scheme, the method comprises the following steps that S10, a system is initialized; s20, the data applicant generates public and private keys; s30, verifying the legality of the public key; s40, aggregating user attributes and public keys; s50, encrypting the data to be shared and the keywords; s60, retrieving the shared ciphertext matched with the keyword; and S70, the data applicant decrypts the authorized ciphertext. A retrieval encryption mechanism based on registration attributes is constructed, the problem that an existing retrieval encryption method based on attributes depends on a single-point fault of a trusted key distribution center is avoided, fine-grained authorization of shared data and fine-grained retrieval in a ciphertext state are achieved on the premise that privacy of retrieval keywords is protected, and decryption efficiency is improved.
Owner:NANTONG UNIV

Blockchain-based smart grid data security sharing and quality evaluation method

PendingCN122333436AContent IdentifierData set
This invention discloses a blockchain-based method for secure data sharing and quality assessment in smart grids, belonging to the field of data security sharing technology. The method includes: system initialization and user registration, where a key distribution center distributes keys and blockchain addresses to data owners, researchers, and a quality assessment platform; data collection and uploading, where data owners encrypt datasets, generate content identifiers in blocks, store them in IPFS, and upload the stored information to the blockchain to form trusted evidence; smart contracts and access control, setting access policies and issuing access tokens to verified researchers to obtain the dataset; dataset quality assessment, generating and providing feedback on a quality report by combining label reordering, correlation coefficient testing, and performance evaluation testing; and a reward mechanism, allocating reputation values ​​and rewards to data owners based on dataset quality. This invention achieves secure and trusted data sharing and scientific quality assessment, promoting the continuous provision of high-quality data.
Owner:NANJING UNIV OF POSTS & TELECOMM

Multi-receiver bilateral access control privacy protection cross-domain data sharing method

The invention discloses a multi-receiver bilateral access control privacy protection cross-domain data sharing method. The method comprises the following steps: executing system parameter initialization by a total trusted center and generating a master key; generating respective key pairs for the trusted center, the key distribution center and the vehicle based on the master key and the public parameters; the sender vehicle generates a common original encrypted ciphertext for the target receiver vehicle set by using the private key of the sender vehicle and the public key of the receiver; the receiver vehicle decrypts the ciphertext by using the private key of the receiver vehicle and the public key of the sender; and in a cross-domain sharing scene, the road side unit safely converts the original ciphertext into a re-encrypted ciphertext through the re-encrypted key, so that a target domain receiver can decrypt the re-encrypted ciphertext. According to the method, fine-grained bilateral access control and privacy protection in a cross-domain environment are realized, on the premise of ensuring data security, the calculation and communication overhead of one-to-many encryption is remarkably reduced, complex certificate management is avoided, and the efficiency and practicability of Internet of Vehicles data sharing are improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV