Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

71 results about "Key encapsulation" patented technology

Key encapsulation mechanisms (KEMs) are a class of encryption techniques designed to secure symmetric cryptographic key material for transmission using asymmetric (public-key) algorithms. In practice, public key systems are clumsy to use in transmitting long messages. Instead they are often used to exchange symmetric keys, which are relatively short. The symmetric key is then used to encrypt the longer message.

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Over-the-air upgrade method and device, and storage medium

The invention provides an over-the-air upgrade method and device, and a storage medium. The method comprises the following steps: an over-the-air upgrade server splits an over-the-air upgrade package into a plurality of data blocks; respectively adding signature data to each data block; when adding of the signature data is completed, using a plurality of block keys to perform chain encryption on a plurality of data blocks and transmitting a non-first block key in a staggered manner to obtain a ciphertext block, and packaging the first block key into a digital envelope; sending the digital envelope and the plurality of ciphertext blocks to a target device; the target device reads the first block key in the digital envelope, chains the plurality of ciphertext blocks according to the first block key and extracts a staggered non-first block key to obtain a plurality of data blocks; respectively verifying the signature data in each data block; and when the multiple pieces of signature data are verified successfully, assembling the multiple data blocks into an over-the-air upgrade package, and upgrading by using the over-the-air upgrade package. According to the embodiment of the invention, gradual decryption is realized through a chain dependency mechanism, so that the security of OTA upgrading is effectively improved.
Owner:HUNAN KAIHONG ZHIGU DIGITAL IND DEV CO LTD

Wireless terminal security control method and system

The invention discloses a wireless terminal security management and control method and system, and relates to the technical field of power system communication security. The method comprises the following steps: in a communication connection establishment stage, establishing a shared key through WAPI bidirectional authentication and post quantum key encapsulation, and initializing a physical layer waveform parameter synchronization mechanism; in the security situation assessment stage, collected equipment characteristics, near field communication and electromagnetic environment data are fused, quantitative analysis is performed through a neural network and an attack graph model, and a dynamic security threat level is obtained; in the security policy execution stage, the security policy and physical layer parameters are adaptively adjusted according to the threat level and the channel assessment result to form closed-loop management and control. According to the method, the problems of single protection means, response lag and lack of quantum safety capability of a traditional scheme in complex environments such as a new energy station are solved, and active, accurate and self-adaptive wireless terminal safety protection is realized.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Secure device communication using mult-key encapsulation

A method for establishing secure communication between a first device and a second device. The method includes generating ephemeral keys at the first device, encapsulating a public key of the second device to generate a first cipher key and a first shared secret key, transmitting a first message to the second device including the ephemeral public key and the first cipher key, receiving a second message from the second device containing a second cipher key, decapsulating the second cipher key to achieve a second shared secret key, receiving and decapsulating a third cipher key to achieve a third shared secret key, deriving a final encryption key using the first, second, and third shared secret keys, and establishing secure communication by encrypting communication using the final encryption key. The method further includes verifying the final encryption key with the second device through hash exchange.
Owner:AAPOON INC

Efficient key encapsulation method based on modular fault-tolerant rounding problem

The invention relates to the technical field of cryptography, and belongs to an efficient key encapsulation method based on a modular fault-tolerant rounding problem, which adopts an improved key generation process and introduces an efficient coding strategy so as to obviously reduce the sizes of a public key and a private key and the calculation overhead required in the generation process, and improve the key encapsulation efficiency. The communication efficiency and the calculation efficiency are considered while high safety intensity is kept, and a feasible and easy-to-implement solution is provided for information protection in a quantum calculation environment. According to the method and the device, the security strength can be improved, the key generation efficiency and the decryption efficiency are considered, and the method and the device have good expansibility and easiness in implementation.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Method and apparatus for performing client credential assertion in wireless communication system

The present disclosure relates to a 5th-Generation (5G) communication system or a 6th-Generation (6G) communication system for supporting higher data rates beyond a 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure provides techniques for performing authentication and authorization based on client credential assertion in a wireless communication system. A method performed by a network entity for performing client credential assertion (CCA)-based authentication and authorization of the network entity is provided. In one embodiment, a method includes sending, by a network entity, a first service request to a network repository function (NRF), where sending of the first service request includes encrypting, by the network entity, a CCA token using a Key Encapsulation Mechanism (KEM), where the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, where the KEM is based on the PQC mechanism. The encrypted CCA token is signed by the network entity using a digital signature to generate a quantum-secure CCA token, where the quantum-secure CCA token is a digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-secure CCA token to the NRF along with the first service request, where the quantum-secure CCA token is the digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism. And receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Systems and methods for AI directed tiered post quantum protection of multimodal data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC

Key security migration and centralized distribution method for distributed virtualization scenarios

This invention relates to the field of key management technology and discloses a method for secure key migration and centralized distribution in distributed virtualization environments. The system works collaboratively with a centralized key management service (CKMS) and a local security module (LSM). When LSM detects virtual instance migration, CKMS, based on a multi-dimensional dynamic trust assessment mechanism, approves key migration only when the risk of the target node meets the threshold. Subsequently, CKMS generates an encrypted drift key encapsulation structure (DKE) and securely transmits it to the target node via an optimized path, while the source node securely deletes the original key. Furthermore, CKMS synchronously maintains global key version consistency and utilizes graph structure anomaly detection technology to identify potential threats by analyzing the operation relationship graph. This invention achieves secure, controllable flow and centralized management of keys during the migration process.
Owner:GUANGXI POWER GRID CORP

Satellite communication data encryption method based on quantum encryption

The invention discloses a satellite communication data encryption method based on quantum encryption, and the method comprises the steps: generating a unique session identifier, and synchronizing system time to mark a secret key negotiation session; obtaining a standardized key encapsulation data stream; generating a segmentation strategy parameter set according to the low-orbit satellite link parameter set; the short frame data segment and the short frame header field are combined to form a header short frame data segment; generating an error correction short frame data segment, and forming a to-be-sent satellite link frame; performing recombination management according to the session identifier and the short frame serial number; sequentially splicing the short frame data segments with heads according to the short frame serial numbers, and recombining into a second standardized key encapsulation data stream; and generating a shared key, cancelling the shared key and releasing the link resource by the two parties according to the session identifier after the service data transmission is completed, and ending the key negotiation session. According to the method, the loss rate of the core control section of the protocol session can be reduced to below 1 / 10 under the typical low-orbit satellite overhead link.
Owner:SHENZHEN XINSHENG INTELLIGENT INFORMATION CO LTD

Layered encryption storage method for hot and cold data of Internet of Vehicles with post-quantum security

The invention relates to the technologies of Internet of Vehicles, block chains, consensus algorithms and the like, discloses an Internet of Vehicles cold and hot data hierarchical encryption storage method with post-quantum security, and relates to the technical field of Internet of Vehicles data security and post-quantum cryptography. According to the method, full-link encryption of cold and hot data is realized through cooperation of a Kyber-512 key encapsulation mechanism and AES symmetric encryption, on-chain evidence storage and identity authentication are completed in combination with an ML-DSA-44 signature algorithm, hot data are stored by adopting a local cache, and cold data are stored by adopting IPFS distributed storage and a block chain. According to the method, the problems of insufficient quantum attack resistance, low storage efficiency, complicated key management and the like in the traditional Internet of Vehicles storage are solved, unification of data confidentiality, integrity and traceability is realized, and vehicle-mounted resource constraint characteristics are adapted.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Key dynamic generation and distribution method and system based on one-way channel

The invention relates to a secret key dynamic generation and distribution system based on a one-way channel. The system comprises an intranet side secret key generation module, a secret key packaging and signing module and a video sending module. An extranet side video receiving module, a secret key analysis and verification module and an extranet security agent module; and a unidirectional transmission link; the key generation module is used for dynamically generating a key; the key packaging and signature module is used for packaging, and a packaging structure comprises a key serial number, a check code, a frame header, a timestamp and a digital signature; the video sending module is connected with the key packaging and signing module and is used for mapping the packaged key packet into a video signal and outputting the video signal to the one-way transmission link; the one-way transmission link is used for transmitting the video signal from the video sending module to the video receiving module; the video receiving module is used for extracting the key packet; and the key analysis and verification module is used for verifying the received key packet. According to the invention, dynamic, safe and high-speed key distribution can be realized.
Owner:ZEN-AI TECH

Optimized bit flipping key encapsulation post-quantum cryptographic method

Optimized BIKE method comprising: setting system parameters and Hash functions; generating a public key () and a private key (); encapsulating a message (m) into a ciphertext (c) using the public key, and computing a pseudo-message (K) using the message and the ciphertext; and, decapsulation the ciphertext using the private key to retrieve the pseudo-message. The method computes a product between first and second operands of a size n binary polynomial type by way of a pointwise product between first and second transformed operands resulting in an AFFT like function applied to the first and second operands respectively, so that at least one element among the first private element ({umlaut over (h)}0) of the private key () or the single public element ({umlaut over (h)}) of the public key () is a vector in the AFFT domain.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Methods for securing communication between two communication partners in a vehicle ecosystem

The invention relates to a method for securing communication between two communication partners of a vehicle ecosystem beyond the time of occurrence of a post-quantum threat (PQ), for which a key is exchanged between the communication partners by means of authenticity-protected communication before the occurrence of the post-quantum threat (PQ). The invention is characterized in that a hybrid key encapsulation method is used for exchanging the key, by which a conventional key and a post-quantum resistant key are exchanged, from which a hybrid key is then formed by means of a derivation procedure, wherein after the exchange of the two key components of the hybrid key the possibility of exchange is locked or deleted.
Owner:MERCEDES BENZ GROUP AG

Medical data security protection method and system based on block chain

The invention discloses a medical data security protection method and system based on a block chain, and relates to the technical field of computer information security. The method comprises the following steps: generating a shared key and a key encapsulation ciphertext by adopting an anti-quantum key encapsulation mechanism and a data receiver public key; encrypting the medical data by adopting a shared key and a symmetric encryption algorithm to obtain a data ciphertext; processing the data ciphertext into N data fragments which can be reconstructed based on any K data fragments; storing the N data fragments in a distributed storage system, and storing fragment content hash values and recovery information in a block chain; when the data is recovered, information is acquired from the block chain, and at least K fragment reconstruction data ciphertexts are acquired from the distributed storage system; and recovering the shared key by adopting the key encapsulation ciphertext and the private key of the data receiver through anti-quantum key de-encapsulation operation, and decrypting the data ciphertext to obtain the medical data. The invention aims to provide a security protection method which can resist future quantum computing attacks and can ensure high availability and high integrity of medical data.
Owner:ANHUI UNIV

Mixed attribute base searchable signcryption method

The invention provides a mixed attribute base searchable signcryption method, and relates to the technical field of cryptography. The method comprises the steps that a decryptor encrypts a retrieval keyword according to a classic decryption key to generate a search token and sends the search token to a cloud server; wherein the classic decryption key is information obtained by encrypting a decryption attribute set of a decryptor by the key generation center; the cloud server adopts a cloud private key, searches a target hybrid ciphertext matched with the keyword from the keyword components of the plurality of hybrid ciphertexts according to the search token, and sends the target hybrid ciphertext to a decipherer; each hybrid ciphertext is information obtained after the signcryption person encrypts the message to be signcrypted and the keyword information of the message to be signcrypted according to the post-quantum public key; and the decryptor decrypts the target hybrid ciphertext by using the post-quantum private key and determines the message to be signcrypted, and the post-quantum public key and the post-quantum private key are keys pre-generated by the key generation center. According to the invention, fusion of an anti-quantum key encapsulation mechanism and an attribute-based searchable encryption technology can be realized.
Owner:中电信量子信息科技集团有限公司

Iot security access method based on anti-quantum identity authentication and key encapsulation

The application provides an anti-quantum identity authentication and key encapsulation based Internet of Things security access method, which comprises the following steps: a client sends a first message to a server, wherein the first message comprises a first ciphertext sharing key and a first key parameter; the server performs an unsealing operation on the first ciphertext sharing key based on a server private key to obtain a first sharing key; a key derivation operation is performed on the first sharing key to obtain a first session key; a decryption operation is performed on the first key parameter based on the first session key to obtain a second dynamic identity and a second static public key; the server generates a third static public key based on the second dynamic identity; if the third static public key matches the second static public key, it is determined that the anti-quantum identity authentication of the server is successful; if the third static public key does not match the second static public key, it is determined that the anti-quantum identity authentication of the server fails. Through the technical scheme of the application, the calculation burden of the authentication process can be reduced, and the application is suitable for resource-limited devices.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

A collaborative asset management system based on end-to-end encryption

This invention relates to the fields of information security and computer software technology, and discloses a collaborative asset management system based on end-to-end encryption, employing a zero-knowledge architecture with client-server collaboration. The client creates a collaborative space and generates a space key. For sensitive credentials, it generates a content key to form credential ciphertext and content key encapsulated ciphertext. During access, a controlled-use proxy decapsulates the content key encapsulated ciphertext in a local controlled execution environment to obtain the content key, completing controlled credential use and thus preventing the plaintext credential from being exposed to external programs. The server stores the space key encapsulated ciphertext, credential ciphertext, content key encapsulated ciphertext, and directory and policy information. Through a proxy re-encryption (ciphertext domain conversion) module, the space key encapsulated ciphertext is converted into ciphertext that new members can decapsulate without decrypting the plaintext key, enabling dynamic member addition without re-encrypting and retransmitting all credentials. The system registers capability declarations through extended module interfaces to describe heterogeneous asset access capabilities. Based on this, the client selects a connector and executes a blind injection / proxy call authentication process. At the same time, audit events are encrypted and their integrity is protected by hash chains or digital signatures. The server only stores audit ciphertext and non-sensitive index fields, thereby achieving collaborative management, controllable use, and scalable access under zero-knowledge conditions.
Owner:王华

Document sensitive fragment dynamic hierarchical encryption method based on content semantic features

The invention relates to a dynamic hierarchical encryption method for document sensitive fragments based on content semantic features. The method comprises the following steps: carrying out structured fragmentation modeling on to-be-protected document data to obtain sensitive fragment data and structure context data; performing multi-modal semantic representation construction on the sensitive fragment data and the structure context data to obtain content semantic representation data and irreversible semantic sketch ciphertext data; performing hierarchical state calculation on the content semantic representation data and the irreversible semantic sketch ciphertext data to obtain hierarchical state data; performing hierarchical binding double-layer envelope authentication encryption by combining the sensitive fragment data and the hierarchical state data to obtain fragment ciphertext data and key encapsulation ciphertext data; and carrying out encapsulation layer strategy rebinding updating on the fragment ciphertext data and the key encapsulation ciphertext data to obtain encrypted document data. By adopting the method, the security of the sensitive fragment of the document can be improved.
Owner:NANJING DAOCHENG NETWORK TECH CO LTD

A method of key encapsulation and encryption and decryption based on ntru lattice

The present application belongs to the technical field of lattice cryptography, and particularly relates to a key encapsulation and encryption / decryption method based on an NTRU lattice. The method comprises a public key encryption method and a key encapsulation method. The method is more compact and efficient, and only needs to change three parameters, i.e. ring dimension n, ring modulus q and ciphertext compression parameter d, when changing a parameter set. The key generation, encryption and decryption algorithm structure of the NTRU is simple, and only one polynomial multiplication is needed in the encryption / decryption process. The method has a shorter ciphertext length, does not need error correction code to compress the ciphertext, i.e. does not use error correction code to recover the plaintext, and has stronger security in both classical and quantum models.
Owner:SHANGHAI HONGGEHOU QUANTUM TECHNOLOGY CO LTD

Digital certificate issuing method based on double certificate system and related device

ActiveCN120110678BQuantum algorithmCertificate signing request
Embodiments of the application disclose a digital certificate issuing method and related device based on a double-certificate system, a user terminal generates a first and a second public-private key pair according to an asymmetric encryption algorithm and a post-quantum key signature algorithm respectively; the first and the second public key are taken as a hybrid public key to generate a certificate signature request together with user identification information, and the certificate signature request is sent to a certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key and an encrypted symmetric key according to the certificate signature request; the user terminal decrypts the encrypted hybrid key encapsulation private key and the symmetric key according to the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed and bound with the corresponding private key, so that the hybrid key signature certificate and the hybrid key encapsulation certificate are issued, the legal use of the certificate in a quantum algorithm resistant scenario is ensured, and the information security is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Safe communication authentication method for electric energy meter

The invention discloses a secure communication authentication method for an electric energy meter, and aims to solve the problems that only link encryption is carried out in a multi-level network from an electric meter to a collector to a master station, the collector is visible and changeable, and packets are easy to lose in small-frame fragmentation. According to the method, the entity proof token and the mixed public key are packaged and bound in a hard manner, the key tree is constructed from the object level to the fragment level, the Merkel fragment commitment is used for generating the fragment level initialization parameter and the authentication related data, and the authentication encryption algorithm with the synthesis initialization vector characteristic is used for encryption and integrity protection. And meanwhile, a trusted execution environment monotonic counter is used for preventing rollback, and a system type forward error correction enhancement recovery capability is introduced, so that the technical effects of real end-to-end authentication and encryption, fragment-level insertion modification prevention, rearrangement prevention, truncation prevention, whole message consistency verification and adaptation to out-of-order and packet loss scenes are realized.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Method and apparatus for performing client credential assertion in a wireless communication system

The present disclosure relates to a fifth generation (5G) communication system or a sixth generation (6G) communication system for supporting higher data rates beyond a fourth generation (4G) communication system such as long term evolution (LTE). The present disclosure provides techniques for performing client credential assertion based authentication and authorization in a wireless communication system. A method for performing client credential assertion (CCA) based authentication and authorization of a network entity by a network entity is provided. The method includes sending, by the network entity, a first service request to a network repository function (NRF), wherein the sending of the first service request includes encrypting, by the network entity, a CCA token using a key encapsulation mechanism (KEM), wherein the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, signing, by the network entity, the encrypted CCA token using a digital signature to generate a quantum-safe CCA token, wherein the quantum-safe CCA token is the digitally signed encrypted CCA token, and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-safe CCA token to the NRF along with the first service request, and receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Subscription Concealed Identifier (SUCI) Supporting Post-Quantum Cryptography

A device and a network can authenticate using a subscription concealed identifier (SUCI). The device can store (i) a plaintext subscription permanent identifier (SUPI) for the device, (ii) a network static public key, and (iii) a key encapsulation mechanism (KEM) for encryption using the network static public key. The network can store (i) a device database with the SUPI, (ii) a network static private key, and (iii) the KEM for decryption using the network static private key. The device can (i) combine a random number with the SUPI as input into the KEM to generate a ciphertext as the SUCI, and (ii) transmit the ciphertext / SUCI to the network. The network can (i) decrypt the ciphertext using the KEM to read the SUPI, (iii) select a key K from the device database using the SUPI, and (iv) conduct an Authentication and Key Agreement (AKA) with the selected key K.
Owner:ADEIA EMERGING TECHNOLOGIES INC

Data security sharing method, device, equipment, medium and product

The invention provides a data security sharing method and apparatus, a device, a medium and a product. The method comprises the steps of obtaining an on-chain identity credential of a data requester from a block chain and extracting a public key and an authority level from the on-chain identity credential; then multiple rounds of key packaging operation are executed in advance to generate a plurality of key packaging results so as to construct a pre-packaged key pool; and when a data access request is received, selecting a target key packaging result from the key pool, and dynamically constructing a structured access token according to a target shared key in the target key packaging result and the authority level of a requester. The token and the target encapsulation ciphertext are sent to the data requester together, a data ciphertext is generated and sent, and the data requester can decrypt the data ciphertext in combination with the received token and the encapsulation ciphertext to obtain the shared data. By fusing block chain identity verification, precomputation key encapsulation and a structured token mechanism, fine-grained security access control capable of being dynamically adjusted is realized while security is guaranteed and multi-party data sharing efficiency is improved.
Owner:CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2

WIA-FA secure communication method based on hybrid public key encryption

The invention relates to a WIA-FA secure communication method based on hybrid public key encryption, and belongs to the technical field of communication, and the method comprises the following steps: S1, employing an improved WIA-FA device to safely join a process to establish a public key; s2, establishing a secret key based on a hybrid public key encryption (HPKE) method; and S3, the two communication parties use the newly established session key and the AEAD algorithm to perform encryption and integrity verification on all process data and control commands so as to construct an end-to-end secure communication link. According to the invention, an independent key packaging mechanism is introduced in the handshake stage of the key establishment of the equipment, so that the equipment can realize the confidentiality of a session key when the key is established, and also can generate a data encryption key, a broadcast data key, a unicast data key and a key encryption key which are directly suitable for link layer communication. Therefore, the overall security and flexibility are remarkably improved, and the compatibility with the existing standard message is ensured.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Secret key life cycle management method and related product

The invention discloses a key life cycle management method and a related product. In the scheme, in response to a connection request of a client, double-layer key encapsulation is carried out on initial public key data of the client by utilizing initial key data of a server, and an initial encapsulation result is obtained and sent to the client to enable the client to carry out de-encapsulation; determining a main session key based on a de-encapsulation result sent by the client, and communicating with the client based on the main session key to obtain key use data in a communication process; monitoring key use data, performing key rotation based on a multi-dimensional trigger condition, and determining new key data; performing double-layer key re-encapsulation based on the new key data to obtain a new encapsulation result, and sending the new encapsulation result to the client to enable the client to perform de-encapsulation; and updating the key state based on a new de-encapsulation result sent by the client. Compared with the prior art that a key rotation mode lacks the capability of sensing quantum security threats, the method has obvious advantages.
Owner:太保科技有限公司

Lattice public key data encryption and decryption method and key encapsulation method based on vector decoding

The application discloses a lattice public key data encryption and decryption method and a key encapsulation method based on vector decoding. The method comprises the following steps: obtaining first target ciphertext data according to predetermined plaintext data, a first predetermined encryption method, a first target public key and a predetermined interference term, so that lattice public key data encryption can be realized; obtaining target plaintext data according to the first target ciphertext data, a first target private key and a predetermined decryption method, so that lattice public key data decryption can be realized. Meanwhile, the application also proposes a variant problem of a ring learning with errors problem (RLWE), namely, a subset-sum parity RLWE (sspRLWE) problem, and further optimizes the lattice public key data encryption method based on vector decoding in the application based on the variant problem. The public key encryption method and the key encapsulation method designed in the application have the characteristics and advantages of provable security, resistance to quantum computer attacks, short public key and ciphertext length, high calculation efficiency, low decryption failure rate, flexible parameter selection and the like.
Owner:BEIJING ACAD OF INFORMATION SCI & TECH

Identity binding confirmation code based anti-skip verification key encapsulation method and device

The application provides an anti-skip verification key encapsulation method and device based on an identity binding confirmation code, which comprises the following steps: a second device performs a decryption operation on a first ciphertext parameter based on a private key to obtain a second target character sequence; the second target character sequence is encrypted based on a public key to obtain a second ciphertext parameter; if the second ciphertext parameter is different from the first ciphertext parameter, the second device determines that the key encapsulation verification of the second device fails; if the second ciphertext parameter is the same as the first ciphertext parameter, the second device generates a second identity binding confirmation code based on the second target character sequence and the identity of the second device; if the second identity binding confirmation code is different from a first identity binding confirmation code, the second device determines that the key encapsulation verification fails; if the second identity binding confirmation code is the same as the first identity binding confirmation code, the second device determines that the key encapsulation verification succeeds. Through the technical scheme of the application, the safety of data can be ensured.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Just-in-time post-quantum cryptography (PQC) key expansion

The described techniques address issues associated with current post-quantum cryptography (PQC) algorithms by providing a more efficient means of key expansion. Architectures are provided for both an accelerator and an expander, which may be implemented in accordance with any suitable type of cryptographic algorithm that utilizes key expansion, such as PQC algorithms, a key encapsulation mechanism (KEM) algorithm, a Digital Signature Algorithm (DSA), etc. The accelerator architecture enables portions of the expanded key to be generated only when required by a processing block, allowing for the reuse of memory, which allows for a reduction in memory size and thus a smaller footprint (i.e. physical size) compared to conventional architectures. The expander architecture reduces the required interactions and data transfers between the processing block and the key expansion block, thereby reducing the load on the processing block and system components, such as shared buses and bridges.
Owner:INFINEON TECHNOLOGIES AG