Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

142 results about "Key encapsulation" patented technology

Key encapsulation mechanisms (KEMs) are a class of encryption techniques designed to secure symmetric cryptographic key material for transmission using asymmetric (public-key) algorithms. In practice, public key systems are clumsy to use in transmitting long messages. Instead they are often used to exchange symmetric keys, which are relatively short. The symmetric key is then used to encrypt the longer message.

NTRU-based efficient and compact key packaging, encryption and decryption method

The invention discloses an efficient and compact key packaging, encryption and decryption method based on NTRU. The invention belongs to the technical field of lattice passwords, and particularly relates to an NTRU-based secret key packaging, encrypting and decrypting method with scalable ciphertext compression and balanced performance. According to the method, a public key compression and scaling ciphertext compression technology is provided for an NTRU password system, only one polynomial is needed in the encryption and decryption process, and the technology is also suitable for other password schemes based on NTRU. The method has the advantages of being shorter in ciphertext size, more flexible in parameter selection, capable of proving security under classical and quantum random oracle models, tighter in theoretical security protocol advantage, higher in known attack resistance, efficient in implementation, negligible in error rate and the like.
Owner:FUDAN UNIVERSITY

Secure communication method and system based on QRNG and Beidou positioning terminal

The invention provides a secure communication method and system based on a QRNG and a Beidou positioning terminal. A sending end and a receiving end of communication preset a pre-shared initial key, and a space-time reference parameter group is obtained through Beidou positioning; a secret key packaging secret key is generated by using a national secret SM4 algorithm; monitoring time-space parameter deviation in a communication process in real time, and triggering a key updating protocol when the time-space parameter deviation exceeds a threshold value; and after the receiving end verifies the Hash verification value, decrypting to obtain the primary encryption key, and restoring the plaintext data. According to the system, the generated true random number sequence is used as an encryption key, so that the unpredictability and randomness of the key are fundamentally enhanced, and quantum computing attack and man-in-the-middle attack are effectively resisted. The use of the pre-shared key mechanism and the key packaging key improves the response speed and efficiency of the communication system. And meanwhile, the position parameter and the timestamp are deeply fused to the key generation process, so that the spatio-temporal information is more difficult to counterfeit, and the defense capability of the system is further improved.
Owner:YIXUNTONG TECH CO LTD

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Configuration parameter processing method, electronic equipment and storage medium

The invention provides a configuration parameter processing method, electronic equipment and a storage medium, and relates to the field of distributed technologies. The method is applied to a configuration center, and comprises the following steps: receiving key packaging information, a configuration parameter ciphertext and storage request information sent by an application server; randomly selecting an unused target unique identifier according to the storage request information, and inputting the target unique identifier, the key packaging information and the configuration parameter ciphertext into a trusted execution environment for processing to obtain an unpackaging result; determining a storage key according to the deblocking result; when it is detected that the hash value to be verified is equal to the encrypted hash value, an identifier ciphertext and a backup ciphertext of the target unique identifier are obtained through calculation, and the identifier ciphertext is sent to the application server side; and storing the identification hash value and the configuration parameter ciphertext into a parameter database, and storing the backup ciphertext and the pre-stored application identification code into a backup database. According to the method, the storage security of the configuration parameters is improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Session key generation method and related apparatus

The application discloses a session key generation method and related device, and relates to the technical field of quantum encryption; when a first SIM card needs to interact information with a second SIM card, a private key team and a public key team can be generated; since the first SIM card is pre-configured with a hybrid key encapsulation algorithm, the public key team includes a public key that can resist quantum attacks, so after the public key team is sent to the second SIM card, the second SIM card can generate key generation information by using an encapsulation algorithm in the hybrid key encapsulation algorithm, encrypt the key generation information by using the public key team, obtain ciphertext information, and send the ciphertext information to the first SIM card; in this way, the first SIM card can decrypt the ciphertext information by using the private key team, obtain the key generation information, and thus obtain a session key.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Multiple post-quantum cryptography key encapsulations with authentication and forward secrecy

A server and a device can conduct mutually authenticated post-quantum cryptography (PQC) key encapsulation mechanisms (KEM) that also support forward secrecy. The device can store a trusted server public key (PK.server) and the server can store a trusted device public key (PK.device). The device can generate (i) a first KEM ciphertext and (ii) a first key with PK.server and encrypt an ephemeral public key (ePK.device) using the first key. The server can generate (i) a second KEM ciphertext and (ii) a second key with ePK.device. The server can generate (i) a third KEM ciphertext and (ii) a third key with PK.device. The server can encrypt an ephemeral public key (ePK.server) using the first, second, and third keys. The device can generate (i) a fourth KEM ciphertext and (ii) a fourth key with ePK.server. The device can encrypt application data using at least the first, second, third, and fourth keys.
Owner:ADEIA EMERGING TECHNOLOGIES INC

Quantum key distribution method and system after satellite communication based on QUIC

The invention discloses a quantum key distribution method and system after satellite communication based on QUIC, and belongs to the field of information security. The method comprises the steps that a two-stage key distribution method is designed, in the first stage, a ground control terminal sends a public key in a public and private key pair generated by a post-quantum key encapsulation algorithm to a satellite terminal requesting to initiate, and the ground control terminal retains a corresponding private key; wherein the public key is used for generating an application key and a key ciphertext, and the private key is used for decrypting the key ciphertext to obtain the corresponding application key; in the second stage, exchange of application keys of the ground control terminal and the satellite terminal is completed; a two-stage key distribution method is integrated with a QUIC protocol, and a next-generation post-quantum encryption algorithm is introduced into the QUIC protocol. The method has the capability of resisting future quantum computing attack, can reduce the computing consumption of the satellite terminal, is low in transformation and migration cost, and is also suitable for multi-scene adaptive use.
Owner:ZHEJIANG LAB

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Lightweight hybrid encryption transmission method and system capable of resisting quantum attack

The invention discloses an anti-quantum-attack lightweight hybrid encryption transmission method and system, and aims to solve the problems that an existing lattice-based encryption algorithm is complex in calculation, high in resource consumption and difficult to adapt to embedded equipment and an internet of things scene. According to the method, a key encapsulation mechanism is constructed based on an LWE problem, key negotiation is performed by using the quantum attack resistance of the key encapsulation mechanism, and encryption transmission is performed on data in combination with a lightweight symmetric encryption algorithm. In the de-encapsulation process, a rapid dimension reduction decoding mechanism is introduced, and dimension reduction mapping is performed on a high-dimensional ciphertext vector and a private key vector through a mapping matrix obtained through training, so that the matrix operation complexity is reduced, and the decryption efficiency is improved. According to the method, the implementation cost and operation burden of an algorithm on an embedded platform can be remarkably reduced while anti-quantum security is kept, and the method is suitable for an Internet of Things terminal, an edge computing node and other low-power-consumption equipment sensitive to security and energy consumption and has good security, light weight and deployment practicability.
Owner:WUXI ALEADER INTELLIGENT TECH

Configurable module-lattice post-quantum cryptography processor for key-encapsulation mechanism

Disclosed is a reconfigurable module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system and method using memory-based numbers theoretic transform (NTT). A post-quantum cryptography method of a post-quantum cryptography system including a plurality of internal submodules includes reconfiguring the plurality of internal submodules by variably selecting one security level from among the plurality of security levels; reconfiguring execution of the plurality of internal submodules to be changed through a main controller; and variably processing data according to the selected security level to perform key generation, encapsulation, and decapsulation through the reconfigured plurality of internal submodules.
Owner:INHA UNIV RES & BUSINESS FOUNDATION

System and methods for secure communication using post-quantum cryptography

A server and a device can conduct a secure session with (i) multiple post-quantum cryptography (PQC) key encapsulation mechanisms (KEM) and (ii) forward secrecy. The device can store a server static public key (PK.server) before establishing a secure session with the server. The device can use PK.server to encrypt a device ephemeral public key (ePK.device) into a first ciphertext. The first ciphertext can also include a device digital signature. The server can receive and decrypt the first ciphertext. The server can use the ePK.device to encrypt a server ephemeral public key (ePK.server) into a second ciphertext. The second ciphertext can also include a server digital signature. The device can receive and decrypt the second ciphertext. The device can encrypt application data into a third ciphertext using both PK.server and ePK.server. PK.server can support a first PQC algorithm and ePK.server can support a different, second PQC algorithm.
Owner:ADEIA EMERGING TECHNOLOGIES INC

Key negotiation method and system and computer equipment

The invention relates to a key negotiation method and system and computer equipment. The method comprises the following steps: acquiring first vehicle driving information and a post quantum public key; according to the post-quantum public key, based on a post-quantum encapsulation algorithm, performing encapsulation operation to obtain key encapsulation information and a first key; transmitting the secret key packaging information to the vehicle end, so that the vehicle end obtains a second secret key according to the rear quantum private key and the secret key packaging information, and updates a second session key according to the second secret key and the first vehicle driving information; and updating the first session key according to the first key and the first vehicle driving information. The post-quantum key has the characteristic of quantum attack resistance, the first key and the second key are transmitted through the post-quantum key, and the first session key and the second session key are updated in combination with the first vehicle driving information, so that the security during session key negotiation is improved, and the session key is prevented from being leaked.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Post-quantum key packaging method based on modular lattice and lattice coding technology

The invention belongs to the technical field of post-quantum cryptography, and particularly relates to a post-quantum key encapsulation method based on modular lattices and lattice coding. The method disclosed by the invention comprises a scale nested lattice code encoding and decoding method based on a Barnes-Wall lattice; an IND-CPA security public key encryption method is adopted; an IND-CCA security key packaging method is adopted; according to the method, a scale nested lattice code encoding and decoding method based on Barnes-Wall lattices is constructed, and a novel error correction mechanism and a ciphertext compression technology are introduced, so that the limitation of an existing lattice-based secret key packaging algorithm on bandwidth performance is broken through, the decryption error rate is reduced, and the communication efficiency and safety are improved. Besides, the method has flexible parameter selection capability, and adaptive parameter configuration can be provided for different security levels so as to meet security requirements of various application scenes.
Owner:FUDAN UNIVERSITY

TLS1.3 protocol security enhancement method and system based on homologous cryptographic algorithm

The invention discloses a TLS1.3 protocol security enhancement method and system based on a homologous cryptographic algorithm, and the method comprises the steps: 1), certificate generation: signing and issuing a certificate through an SQISign signature algorithm, and guaranteeing the verification and use of a post-quantum security signature algorithm through the certificate; and 2) protocol design: the client and the server complete identity verification through certificate verification based on an SQISign signature algorithm in a handshake stage of a TLS 1.3 protocol. And the server uses a FleS public key encryption algorithm to carry out key encapsulation and send the key encapsulation to the client, completes key exchange and establishes secure encryption connection with the client. The step 1) and the step 2) comprise compatibility design, and a homology-based post-quantum algorithm and a traditional cryptographic algorithm are allowed to coexist, so that the compatibility of an existing system is ensured. Through the method provided by the invention, the TLS 1.3 protocol can effectively resist security threats brought by quantum computing, the security of network communication in the quantum era is ensured, and meanwhile, the smooth transition of the existing system is ensured.
Owner:WUHAN UNIV

Construction method of hybrid key encapsulation mechanism

The invention discloses a construction method of a hybrid key encapsulation mechanism, which comprises the following steps of: generating a public and private key pair of two PKE (Public Key Exchange) algorithms based on security parameters, and outputting a public and private key pair of the hybrid key encapsulation mechanism; taking a public key of a mixed key encapsulation mechanism as the input of an encapsulation algorithm, randomly selecting two plaintexts, respectively generating ciphertexts through public key encryption algorithms of two PKE algorithms, deriving a shared key through a key derivation function, and outputting the shared key; and taking the ciphertext and the private key of the mixed key encapsulation mechanism as the input of a de-encapsulation algorithm, and outputting a shared key. According to the method, a construction method based on the KEM is not used any more, universal construction of the hybrid KEM based on the PKE scheme is achieved, multiple PKE schemes can be adopted for instantiation, multi-level safety under classical and quantum models is achieved, a key derivation function of the KEM for achieving CPA and CCA safety only depends on a plaintext part, and therefore the key derivation function of the hybrid KEM is independent of the plaintext part. Running efficiency is improved by simplifying hash operations and removing redundant hash operations.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

One-way data transmission method and system between physical isolation networks based on national cryptographic algorithm

The invention discloses a one-way data transmission method and system between physical isolation networks based on a national cryptographic algorithm, and relates to the technical field of computer information network security, the method comprises the following steps: a sending terminal processes an encrypted public key and a random number by using an SM9 algorithm, and displays an obtained secret key packaging two-dimensional code; the receiving terminal carries out decoding verification on the key packaging two-dimensional code, and if the verification is passed, a packaging key is obtained; the sending terminal encrypts the original data by using an SM4GCM algorithm to obtain a ciphertext, performs RaptorQ coding on the ciphertext to obtain redundant data fragments, performs coding processing on the auxiliary information and the redundant data fragments, and displays an obtained two-dimensional code sequence; the receiving terminal performs decoding verification on the two-dimensional code sequence, and if the verification is passed, decrypted data is obtained; the Hash value of the decrypted data is calculated through the SM3 algorithm, if the Hash value of the decrypted data is consistent with the Hash value of the original data, data transmission is completed, and safe, efficient and reliable data transmission can be achieved.
Owner:GUIZHOU UNIV

Anti-quantum identity authentication and key encapsulation-based secure access method for Internet of Things

The invention provides an Internet of Things secure access method based on anti-quantum identity authentication and key encapsulation, and the method comprises the steps that a client side sends a first message to a server side, and the first message comprises a first ciphertext shared key and a first key parameter; the server performs an unsealing operation on the first ciphertext shared key based on the server private key to obtain a first shared key; performing key derivation operation on the first shared key to obtain a first session key; decrypting the first key parameter based on the first session key to obtain a second dynamic identity and a second static public key; the server generates a third static public key based on the second dynamic identity label; if the third static public key is matched with the second static public key, determining that anti-quantum identity authentication of the server is successful; and if the third static public key is not matched with the second static public key, determining that the anti-quantum identity authentication of the server fails. Through the technical scheme of the invention, the calculation burden of the authentication process can be reduced, and the method is suitable for resource-constrained equipment.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Domestic post-quantum key packaging method based on lattice

The invention discloses a lattice-based domestic post-quantum key packaging method, which comprises an initial step, a key generation step, an encryption step and a decryption step, and is characterized in that S1, the initial step is as follows: a terminal and a server presets packaging parameters corresponding to a post-quantum password security level, appoints compression and decompression rules of ciphertext data, and sends the packaging parameters to the server; the compression rule adopts a mode based on bit shift operation, and the decompression rule corresponds to reverse operation of the compression rule; the terminal generates a public key element and a private key through the seed and sampling, the public key is uploaded to the server side, the public key comprises a first public key element and a second seed, and the private key comprises a private key vector. And a traditional SHA3 series hash function is replaced by a CBC expansion mode based on SM4, so that the parallel performance of the algorithm is improved.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Over-the-air upgrade method and device, and storage medium

The invention provides an over-the-air upgrade method and device, and a storage medium. The method comprises the following steps: an over-the-air upgrade server splits an over-the-air upgrade package into a plurality of data blocks; respectively adding signature data to each data block; when adding of the signature data is completed, using a plurality of block keys to perform chain encryption on a plurality of data blocks and transmitting a non-first block key in a staggered manner to obtain a ciphertext block, and packaging the first block key into a digital envelope; sending the digital envelope and the plurality of ciphertext blocks to a target device; the target device reads the first block key in the digital envelope, chains the plurality of ciphertext blocks according to the first block key and extracts a staggered non-first block key to obtain a plurality of data blocks; respectively verifying the signature data in each data block; and when the multiple pieces of signature data are verified successfully, assembling the multiple data blocks into an over-the-air upgrade package, and upgrading by using the over-the-air upgrade package. According to the embodiment of the invention, gradual decryption is realized through a chain dependency mechanism, so that the security of OTA upgrading is effectively improved.
Owner:HUNAN KAIHONG ZHIGU DIGITAL IND DEV CO LTD

A compact reusable method of quantum key encapsulation

The application provides an anti-quantum key packaging method with compact reusability, which comprises the following steps: in step 1, a public key encryption scheme with IND-CPA security is designed based on the RLWE problem on a non-two-power cyclotomic ring through a security parameter, public parameters, a public key and a private key are generated, and the public parameters and the public key are published; in step 2, a secret random tape is used to encrypt a plaintext message into a ciphertext based on the obtained public parameters and the public key; and in step 3, the ciphertext is decrypted through the private key to obtain a corresponding plaintext. The method uses the Nussbaumer technique to realize the reusable NTT algorithm, uses the Karatsuba technique to realize the fast multiplication on a small convolution ring, and designs the reusable NTT algorithm for the public ring structure, and has the advantages of simple realization, low resource consumption and the like in the software and hardware implementation and optimization.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Wireless terminal security control method and system

The invention discloses a wireless terminal security management and control method and system, and relates to the technical field of power system communication security. The method comprises the following steps: in a communication connection establishment stage, establishing a shared key through WAPI bidirectional authentication and post quantum key encapsulation, and initializing a physical layer waveform parameter synchronization mechanism; in the security situation assessment stage, collected equipment characteristics, near field communication and electromagnetic environment data are fused, quantitative analysis is performed through a neural network and an attack graph model, and a dynamic security threat level is obtained; in the security policy execution stage, the security policy and physical layer parameters are adaptively adjusted according to the threat level and the channel assessment result to form closed-loop management and control. According to the method, the problems of single protection means, response lag and lack of quantum safety capability of a traditional scheme in complex environments such as a new energy station are solved, and active, accurate and self-adaptive wireless terminal safety protection is realized.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Public key cryptosystem presented by means of a key encapsulation mechanism based on the subset sum problem

PCT designated stageWO2025172629A1Public key infrastructure trust modelsSubset sum problemEngineering
The present invention relates to an asymmetric cryptosystem and cryptographic method with a key encapsulation mechanism based on the subset sum problem and in which the private key is described based on the initial parameters n, t and z, and made up of the positive integers pl,..., pn, g and u. The invention is characterised in that said positive integers meet the following conditions: pl,..., pn are relatively prime to each other and they are not divisible by any prime number less than z; 2q< √g, where q is the product of ql,... qt and qt, the t largest integers of the set {pl,..., pn}. 2p <√(g); where p = (z -1) ∑(i=l, t) q / qi; u is a positive integer less than g and the public key is made up of integer numbers ti,..., tn, characterised in that said positive integers meet the conditions pi(ti + u) = 1 mod g for all i = 1,..., n.
Owner:UNIV DE GRANADA

Quantum-Resistant Password-Authenticated Key Exchanges

Techniques are disclosed relating to quantum resistant cryptography. In some embodiments, a shared secret is established for secure communication between a first device and a second device using a hybrid password-authenticated key exchange (PAKE). The hybrid PAKE includes deriving an initial secret using an elliptic-curve key exchange (ECKE) using a generator selected based on a password, encrypting, using the initial secret, a public key of a key encapsulation mechanism (KEM) for transmission to the second device, decrypting, using the initial secret, a ciphertext received from the second device encapsulating the shared secret using the public key, and decapsulating the shared secret from the decrypted ciphertext using a private key of the KEM.
Owner:APPLE INC

Secure device communication using mult-key encapsulation

A method for establishing secure communication between a first device and a second device. The method includes generating ephemeral keys at the first device, encapsulating a public key of the second device to generate a first cipher key and a first shared secret key, transmitting a first message to the second device including the ephemeral public key and the first cipher key, receiving a second message from the second device containing a second cipher key, decapsulating the second cipher key to achieve a second shared secret key, receiving and decapsulating a third cipher key to achieve a third shared secret key, deriving a final encryption key using the first, second, and third shared secret keys, and establishing secure communication by encrypting communication using the final encryption key. The method further includes verifying the final encryption key with the second device through hash exchange.
Owner:AAPOON INC

Efficient key encapsulation method based on modular fault-tolerant rounding problem

The invention relates to the technical field of cryptography, and belongs to an efficient key encapsulation method based on a modular fault-tolerant rounding problem, which adopts an improved key generation process and introduces an efficient coding strategy so as to obviously reduce the sizes of a public key and a private key and the calculation overhead required in the generation process, and improve the key encapsulation efficiency. The communication efficiency and the calculation efficiency are considered while high safety intensity is kept, and a feasible and easy-to-implement solution is provided for information protection in a quantum calculation environment. According to the method and the device, the security strength can be improved, the key generation efficiency and the decryption efficiency are considered, and the method and the device have good expansibility and easiness in implementation.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Method and apparatus for performing client credential assertion in wireless communication system

The present disclosure relates to a 5th-Generation (5G) communication system or a 6th-Generation (6G) communication system for supporting higher data rates beyond a 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure provides techniques for performing authentication and authorization based on client credential assertion in a wireless communication system. A method performed by a network entity for performing client credential assertion (CCA)-based authentication and authorization of the network entity is provided. In one embodiment, a method includes sending, by a network entity, a first service request to a network repository function (NRF), where sending of the first service request includes encrypting, by the network entity, a CCA token using a Key Encapsulation Mechanism (KEM), where the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, where the KEM is based on the PQC mechanism. The encrypted CCA token is signed by the network entity using a digital signature to generate a quantum-secure CCA token, where the quantum-secure CCA token is a digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-secure CCA token to the NRF along with the first service request, where the quantum-secure CCA token is the digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism. And receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for realizing secret key security packaging and storage based on external physical carrier, electronic equipment, computer readable storage medium and computer program product

The invention discloses a method for realizing secret key security packaging and storage based on an external physical carrier, electronic equipment, a computer readable storage medium and a computer program product, the method is applied to a software computing environment lacking effective or compliant hardware password resources, and the method comprises the following steps: receiving a password credential input by a user; generating a password derived key based on the password credential; encrypting and packaging the protection key by using the password derived key to obtain encrypted data of the protection key; storing encrypted data of the protection key in an external physical carrier; when the protection key needs to be used, the software computing environment obtains encrypted data of the protection key from an external physical carrier; receiving a password credential input by a user, and deriving the same password derived key; the encrypted data of the protection key are unpacked by using a password derived key to obtain the protection key; and performing encryption storage or decryption use on the sensitive security data in the software computing environment by using a protection key.
Owner:BAIZHUO INFORMATION TECH CO LTD

Authentication between user equipment and network using a hybrid key exchange

There is provided an apparatus comprising: means for initiating a registration with a serving network in order to establish a session between the apparatus and the serving network, means for receiving, from a network entity, a first public key of first key material that is associated with a home network, wherein the first public key is associated with a post-quantum cryptography key encapsulation mechanism, means for performing an encapsulation for the first public key to derive: a shared secret key, SS, and ciphertext associated with the encapsulation, means for deriving a hybrid shared key, Ks, based on the shared secret key, SS, and a further shared secret key, means for providing, to the network entity, the ciphertext associated with the encapsulation, and means for deriving a master key for the session based on the hybrid shared key, Ks.
Owner:NOKIA TECHNOLOGIES OY

Anti-skipping verification key packaging method and device based on identity binding confirmation code

The invention provides an anti-skipping verification key packaging method and device based on an identity binding acknowledgement code. The method comprises the steps that second equipment carries out decryption operation on a first ciphertext parameter based on a private key to obtain a second target character sequence; performing encryption operation on the second target character sequence based on a public key to obtain a second ciphertext parameter; if the second ciphertext parameter is different from the first ciphertext parameter, the second device determines that the key encapsulation verification of the second device fails; if the second ciphertext parameter is the same as the first ciphertext parameter, the second device generates a second identity binding confirmation code based on a second target character sequence and the identity label of the second device; if the second identity binding confirmation code is different from the first identity binding confirmation code, the second device determines that the secret key packaging verification fails; and if the second identity binding confirmation code is the same as the first identity binding confirmation code, the second device determines that the key encapsulation verification is successful. Through the technical scheme of the invention, the security of the data can be ensured.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Systems and methods for AI directed tiered post quantum protection of multimodal data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC