Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

101 results about "Key encapsulation" patented technology

Key encapsulation mechanisms (KEMs) are a class of encryption techniques designed to secure symmetric cryptographic key material for transmission using asymmetric (public-key) algorithms. In practice, public key systems are clumsy to use in transmitting long messages. Instead they are often used to exchange symmetric keys, which are relatively short. The symmetric key is then used to encrypt the longer message.

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Key negotiation method and system and computer equipment

The invention relates to a key negotiation method and system and computer equipment. The method comprises the following steps: acquiring first vehicle driving information and a post quantum public key; according to the post-quantum public key, based on a post-quantum encapsulation algorithm, performing encapsulation operation to obtain key encapsulation information and a first key; transmitting the secret key packaging information to the vehicle end, so that the vehicle end obtains a second secret key according to the rear quantum private key and the secret key packaging information, and updates a second session key according to the second secret key and the first vehicle driving information; and updating the first session key according to the first key and the first vehicle driving information. The post-quantum key has the characteristic of quantum attack resistance, the first key and the second key are transmitted through the post-quantum key, and the first session key and the second session key are updated in combination with the first vehicle driving information, so that the security during session key negotiation is improved, and the session key is prevented from being leaked.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

One-way data transmission method and system between physical isolation networks based on national cryptographic algorithm

The invention discloses a one-way data transmission method and system between physical isolation networks based on a national cryptographic algorithm, and relates to the technical field of computer information network security, the method comprises the following steps: a sending terminal processes an encrypted public key and a random number by using an SM9 algorithm, and displays an obtained secret key packaging two-dimensional code; the receiving terminal carries out decoding verification on the key packaging two-dimensional code, and if the verification is passed, a packaging key is obtained; the sending terminal encrypts the original data by using an SM4GCM algorithm to obtain a ciphertext, performs RaptorQ coding on the ciphertext to obtain redundant data fragments, performs coding processing on the auxiliary information and the redundant data fragments, and displays an obtained two-dimensional code sequence; the receiving terminal performs decoding verification on the two-dimensional code sequence, and if the verification is passed, decrypted data is obtained; the Hash value of the decrypted data is calculated through the SM3 algorithm, if the Hash value of the decrypted data is consistent with the Hash value of the original data, data transmission is completed, and safe, efficient and reliable data transmission can be achieved.
Owner:GUIZHOU UNIV

Anti-quantum identity authentication and key encapsulation-based secure access method for Internet of Things

The invention provides an Internet of Things secure access method based on anti-quantum identity authentication and key encapsulation, and the method comprises the steps that a client side sends a first message to a server side, and the first message comprises a first ciphertext shared key and a first key parameter; the server performs an unsealing operation on the first ciphertext shared key based on the server private key to obtain a first shared key; performing key derivation operation on the first shared key to obtain a first session key; decrypting the first key parameter based on the first session key to obtain a second dynamic identity and a second static public key; the server generates a third static public key based on the second dynamic identity label; if the third static public key is matched with the second static public key, determining that anti-quantum identity authentication of the server is successful; and if the third static public key is not matched with the second static public key, determining that the anti-quantum identity authentication of the server fails. Through the technical scheme of the invention, the calculation burden of the authentication process can be reduced, and the method is suitable for resource-constrained equipment.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Domestic post-quantum key packaging method based on lattice

The invention discloses a lattice-based domestic post-quantum key packaging method, which comprises an initial step, a key generation step, an encryption step and a decryption step, and is characterized in that S1, the initial step is as follows: a terminal and a server presets packaging parameters corresponding to a post-quantum password security level, appoints compression and decompression rules of ciphertext data, and sends the packaging parameters to the server; the compression rule adopts a mode based on bit shift operation, and the decompression rule corresponds to reverse operation of the compression rule; the terminal generates a public key element and a private key through the seed and sampling, the public key is uploaded to the server side, the public key comprises a first public key element and a second seed, and the private key comprises a private key vector. And a traditional SHA3 series hash function is replaced by a CBC expansion mode based on SM4, so that the parallel performance of the algorithm is improved.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Over-the-air upgrade method and device, and storage medium

The invention provides an over-the-air upgrade method and device, and a storage medium. The method comprises the following steps: an over-the-air upgrade server splits an over-the-air upgrade package into a plurality of data blocks; respectively adding signature data to each data block; when adding of the signature data is completed, using a plurality of block keys to perform chain encryption on a plurality of data blocks and transmitting a non-first block key in a staggered manner to obtain a ciphertext block, and packaging the first block key into a digital envelope; sending the digital envelope and the plurality of ciphertext blocks to a target device; the target device reads the first block key in the digital envelope, chains the plurality of ciphertext blocks according to the first block key and extracts a staggered non-first block key to obtain a plurality of data blocks; respectively verifying the signature data in each data block; and when the multiple pieces of signature data are verified successfully, assembling the multiple data blocks into an over-the-air upgrade package, and upgrading by using the over-the-air upgrade package. According to the embodiment of the invention, gradual decryption is realized through a chain dependency mechanism, so that the security of OTA upgrading is effectively improved.
Owner:HUNAN KAIHONG ZHIGU DIGITAL IND DEV CO LTD

A compact reusable method of quantum key encapsulation

The application provides an anti-quantum key packaging method with compact reusability, which comprises the following steps: in step 1, a public key encryption scheme with IND-CPA security is designed based on the RLWE problem on a non-two-power cyclotomic ring through a security parameter, public parameters, a public key and a private key are generated, and the public parameters and the public key are published; in step 2, a secret random tape is used to encrypt a plaintext message into a ciphertext based on the obtained public parameters and the public key; and in step 3, the ciphertext is decrypted through the private key to obtain a corresponding plaintext. The method uses the Nussbaumer technique to realize the reusable NTT algorithm, uses the Karatsuba technique to realize the fast multiplication on a small convolution ring, and designs the reusable NTT algorithm for the public ring structure, and has the advantages of simple realization, low resource consumption and the like in the software and hardware implementation and optimization.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Wireless terminal security control method and system

The invention discloses a wireless terminal security management and control method and system, and relates to the technical field of power system communication security. The method comprises the following steps: in a communication connection establishment stage, establishing a shared key through WAPI bidirectional authentication and post quantum key encapsulation, and initializing a physical layer waveform parameter synchronization mechanism; in the security situation assessment stage, collected equipment characteristics, near field communication and electromagnetic environment data are fused, quantitative analysis is performed through a neural network and an attack graph model, and a dynamic security threat level is obtained; in the security policy execution stage, the security policy and physical layer parameters are adaptively adjusted according to the threat level and the channel assessment result to form closed-loop management and control. According to the method, the problems of single protection means, response lag and lack of quantum safety capability of a traditional scheme in complex environments such as a new energy station are solved, and active, accurate and self-adaptive wireless terminal safety protection is realized.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Quantum-Resistant Password-Authenticated Key Exchanges

Techniques are disclosed relating to quantum resistant cryptography. In some embodiments, a shared secret is established for secure communication between a first device and a second device using a hybrid password-authenticated key exchange (PAKE). The hybrid PAKE includes deriving an initial secret using an elliptic-curve key exchange (ECKE) using a generator selected based on a password, encrypting, using the initial secret, a public key of a key encapsulation mechanism (KEM) for transmission to the second device, decrypting, using the initial secret, a ciphertext received from the second device encapsulating the shared secret using the public key, and decapsulating the shared secret from the decrypted ciphertext using a private key of the KEM.
Owner:APPLE INC

Secure device communication using mult-key encapsulation

A method for establishing secure communication between a first device and a second device. The method includes generating ephemeral keys at the first device, encapsulating a public key of the second device to generate a first cipher key and a first shared secret key, transmitting a first message to the second device including the ephemeral public key and the first cipher key, receiving a second message from the second device containing a second cipher key, decapsulating the second cipher key to achieve a second shared secret key, receiving and decapsulating a third cipher key to achieve a third shared secret key, deriving a final encryption key using the first, second, and third shared secret keys, and establishing secure communication by encrypting communication using the final encryption key. The method further includes verifying the final encryption key with the second device through hash exchange.
Owner:AAPOON INC

Efficient key encapsulation method based on modular fault-tolerant rounding problem

The invention relates to the technical field of cryptography, and belongs to an efficient key encapsulation method based on a modular fault-tolerant rounding problem, which adopts an improved key generation process and introduces an efficient coding strategy so as to obviously reduce the sizes of a public key and a private key and the calculation overhead required in the generation process, and improve the key encapsulation efficiency. The communication efficiency and the calculation efficiency are considered while high safety intensity is kept, and a feasible and easy-to-implement solution is provided for information protection in a quantum calculation environment. According to the method and the device, the security strength can be improved, the key generation efficiency and the decryption efficiency are considered, and the method and the device have good expansibility and easiness in implementation.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Method and apparatus for performing client credential assertion in wireless communication system

The present disclosure relates to a 5th-Generation (5G) communication system or a 6th-Generation (6G) communication system for supporting higher data rates beyond a 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure provides techniques for performing authentication and authorization based on client credential assertion in a wireless communication system. A method performed by a network entity for performing client credential assertion (CCA)-based authentication and authorization of the network entity is provided. In one embodiment, a method includes sending, by a network entity, a first service request to a network repository function (NRF), where sending of the first service request includes encrypting, by the network entity, a CCA token using a Key Encapsulation Mechanism (KEM), where the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, where the KEM is based on the PQC mechanism. The encrypted CCA token is signed by the network entity using a digital signature to generate a quantum-secure CCA token, where the quantum-secure CCA token is a digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-secure CCA token to the NRF along with the first service request, where the quantum-secure CCA token is the digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism. And receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for realizing secret key security packaging and storage based on external physical carrier, electronic equipment, computer readable storage medium and computer program product

The invention discloses a method for realizing secret key security packaging and storage based on an external physical carrier, electronic equipment, a computer readable storage medium and a computer program product, the method is applied to a software computing environment lacking effective or compliant hardware password resources, and the method comprises the following steps: receiving a password credential input by a user; generating a password derived key based on the password credential; encrypting and packaging the protection key by using the password derived key to obtain encrypted data of the protection key; storing encrypted data of the protection key in an external physical carrier; when the protection key needs to be used, the software computing environment obtains encrypted data of the protection key from an external physical carrier; receiving a password credential input by a user, and deriving the same password derived key; the encrypted data of the protection key are unpacked by using a password derived key to obtain the protection key; and performing encryption storage or decryption use on the sensitive security data in the software computing environment by using a protection key.
Owner:BAIZHUO INFORMATION TECH CO LTD

Anti-skipping verification key packaging method and device based on identity binding confirmation code

The invention provides an anti-skipping verification key packaging method and device based on an identity binding acknowledgement code. The method comprises the steps that second equipment carries out decryption operation on a first ciphertext parameter based on a private key to obtain a second target character sequence; performing encryption operation on the second target character sequence based on a public key to obtain a second ciphertext parameter; if the second ciphertext parameter is different from the first ciphertext parameter, the second device determines that the key encapsulation verification of the second device fails; if the second ciphertext parameter is the same as the first ciphertext parameter, the second device generates a second identity binding confirmation code based on a second target character sequence and the identity label of the second device; if the second identity binding confirmation code is different from the first identity binding confirmation code, the second device determines that the secret key packaging verification fails; and if the second identity binding confirmation code is the same as the first identity binding confirmation code, the second device determines that the key encapsulation verification is successful. Through the technical scheme of the invention, the security of the data can be ensured.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Systems and methods for AI directed tiered post quantum protection of multimodal data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC

Key security migration and centralized distribution method for distributed virtualization scenarios

This invention relates to the field of key management technology and discloses a method for secure key migration and centralized distribution in distributed virtualization environments. The system works collaboratively with a centralized key management service (CKMS) and a local security module (LSM). When LSM detects virtual instance migration, CKMS, based on a multi-dimensional dynamic trust assessment mechanism, approves key migration only when the risk of the target node meets the threshold. Subsequently, CKMS generates an encrypted drift key encapsulation structure (DKE) and securely transmits it to the target node via an optimized path, while the source node securely deletes the original key. Furthermore, CKMS synchronously maintains global key version consistency and utilizes graph structure anomaly detection technology to identify potential threats by analyzing the operation relationship graph. This invention achieves secure, controllable flow and centralized management of keys during the migration process.
Owner:GUANGXI POWER GRID CORP

Satellite communication data encryption method based on quantum encryption

The invention discloses a satellite communication data encryption method based on quantum encryption, and the method comprises the steps: generating a unique session identifier, and synchronizing system time to mark a secret key negotiation session; obtaining a standardized key encapsulation data stream; generating a segmentation strategy parameter set according to the low-orbit satellite link parameter set; the short frame data segment and the short frame header field are combined to form a header short frame data segment; generating an error correction short frame data segment, and forming a to-be-sent satellite link frame; performing recombination management according to the session identifier and the short frame serial number; sequentially splicing the short frame data segments with heads according to the short frame serial numbers, and recombining into a second standardized key encapsulation data stream; and generating a shared key, cancelling the shared key and releasing the link resource by the two parties according to the session identifier after the service data transmission is completed, and ending the key negotiation session. According to the method, the loss rate of the core control section of the protocol session can be reduced to below 1 / 10 under the typical low-orbit satellite overhead link.
Owner:SHENZHEN XINSHENG INTELLIGENT INFORMATION CO LTD

Key encapsulation methods and devices

ActiveCN122226285BComputer hardwarePlaintext
Embodiments of the present application provide a key encapsulation method and device, the method comprising: in response to a key encapsulation request for transmitting data to a receiving end, obtaining a public key corresponding to the receiving end, and encoding a plaintext message to be encapsulated into a message polynomial on a polynomial ring; performing linear compression on the message polynomial using an inverse element of a preset small coefficient polynomial to obtain a compressed plaintext polynomial; generating a first ciphertext component based on a second public key component and an encryption polynomial, and generating a second ciphertext component based on a first public key component and the compressed plaintext polynomial. The encapsulation result containing the first ciphertext component and the second ciphertext component is sent to the receiving end, so that the receiving end uses a corresponding private key to unencapsulate the encapsulation result, obtains the compressed plaintext polynomial, and decodes the compressed plaintext polynomial to restore the plaintext message. This can effectively resist quantum computers, effectively reduce the ciphertext length of the encapsulated plaintext message, and further reduce storage and communication overhead.
Owner:BEIJING INFOSEC TECH CO LTD +1

Layered encryption storage method for hot and cold data of Internet of Vehicles with post-quantum security

The invention relates to the technologies of Internet of Vehicles, block chains, consensus algorithms and the like, discloses an Internet of Vehicles cold and hot data hierarchical encryption storage method with post-quantum security, and relates to the technical field of Internet of Vehicles data security and post-quantum cryptography. According to the method, full-link encryption of cold and hot data is realized through cooperation of a Kyber-512 key encapsulation mechanism and AES symmetric encryption, on-chain evidence storage and identity authentication are completed in combination with an ML-DSA-44 signature algorithm, hot data are stored by adopting a local cache, and cold data are stored by adopting IPFS distributed storage and a block chain. According to the method, the problems of insufficient quantum attack resistance, low storage efficiency, complicated key management and the like in the traditional Internet of Vehicles storage are solved, unification of data confidentiality, integrity and traceability is realized, and vehicle-mounted resource constraint characteristics are adapted.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Key dynamic generation and distribution method and system based on one-way channel

The invention relates to a secret key dynamic generation and distribution system based on a one-way channel. The system comprises an intranet side secret key generation module, a secret key packaging and signing module and a video sending module. An extranet side video receiving module, a secret key analysis and verification module and an extranet security agent module; and a unidirectional transmission link; the key generation module is used for dynamically generating a key; the key packaging and signature module is used for packaging, and a packaging structure comprises a key serial number, a check code, a frame header, a timestamp and a digital signature; the video sending module is connected with the key packaging and signing module and is used for mapping the packaged key packet into a video signal and outputting the video signal to the one-way transmission link; the one-way transmission link is used for transmitting the video signal from the video sending module to the video receiving module; the video receiving module is used for extracting the key packet; and the key analysis and verification module is used for verifying the received key packet. According to the invention, dynamic, safe and high-speed key distribution can be realized.
Owner:ZEN-AI TECH

Optimized bit flipping key encapsulation post-quantum cryptographic method

Optimized BIKE method comprising: setting system parameters and Hash functions; generating a public key () and a private key (); encapsulating a message (m) into a ciphertext (c) using the public key, and computing a pseudo-message (K) using the message and the ciphertext; and, decapsulation the ciphertext using the private key to retrieve the pseudo-message. The method computes a product between first and second operands of a size n binary polynomial type by way of a pointwise product between first and second transformed operands resulting in an AFFT like function applied to the first and second operands respectively, so that at least one element among the first private element ({umlaut over (h)}0) of the private key () or the single public element ({umlaut over (h)}) of the public key () is a vector in the AFFT domain.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Methods for securing communication between two communication partners in a vehicle ecosystem

The invention relates to a method for securing communication between two communication partners of a vehicle ecosystem beyond the time of occurrence of a post-quantum threat (PQ), for which a key is exchanged between the communication partners by means of authenticity-protected communication before the occurrence of the post-quantum threat (PQ). The invention is characterized in that a hybrid key encapsulation method is used for exchanging the key, by which a conventional key and a post-quantum resistant key are exchanged, from which a hybrid key is then formed by means of a derivation procedure, wherein after the exchange of the two key components of the hybrid key the possibility of exchange is locked or deleted.
Owner:MERCEDES BENZ GROUP AG

Medical data security protection method and system based on block chain

The invention discloses a medical data security protection method and system based on a block chain, and relates to the technical field of computer information security. The method comprises the following steps: generating a shared key and a key encapsulation ciphertext by adopting an anti-quantum key encapsulation mechanism and a data receiver public key; encrypting the medical data by adopting a shared key and a symmetric encryption algorithm to obtain a data ciphertext; processing the data ciphertext into N data fragments which can be reconstructed based on any K data fragments; storing the N data fragments in a distributed storage system, and storing fragment content hash values and recovery information in a block chain; when the data is recovered, information is acquired from the block chain, and at least K fragment reconstruction data ciphertexts are acquired from the distributed storage system; and recovering the shared key by adopting the key encapsulation ciphertext and the private key of the data receiver through anti-quantum key de-encapsulation operation, and decrypting the data ciphertext to obtain the medical data. The invention aims to provide a security protection method which can resist future quantum computing attacks and can ensure high availability and high integrity of medical data.
Owner:ANHUI UNIV

Mixed attribute base searchable signcryption method

The invention provides a mixed attribute base searchable signcryption method, and relates to the technical field of cryptography. The method comprises the steps that a decryptor encrypts a retrieval keyword according to a classic decryption key to generate a search token and sends the search token to a cloud server; wherein the classic decryption key is information obtained by encrypting a decryption attribute set of a decryptor by the key generation center; the cloud server adopts a cloud private key, searches a target hybrid ciphertext matched with the keyword from the keyword components of the plurality of hybrid ciphertexts according to the search token, and sends the target hybrid ciphertext to a decipherer; each hybrid ciphertext is information obtained after the signcryption person encrypts the message to be signcrypted and the keyword information of the message to be signcrypted according to the post-quantum public key; and the decryptor decrypts the target hybrid ciphertext by using the post-quantum private key and determines the message to be signcrypted, and the post-quantum public key and the post-quantum private key are keys pre-generated by the key generation center. According to the invention, fusion of an anti-quantum key encapsulation mechanism and an attribute-based searchable encryption technology can be realized.
Owner:中电信量子信息科技集团有限公司

Iot security access method based on anti-quantum identity authentication and key encapsulation

The application provides an anti-quantum identity authentication and key encapsulation based Internet of Things security access method, which comprises the following steps: a client sends a first message to a server, wherein the first message comprises a first ciphertext sharing key and a first key parameter; the server performs an unsealing operation on the first ciphertext sharing key based on a server private key to obtain a first sharing key; a key derivation operation is performed on the first sharing key to obtain a first session key; a decryption operation is performed on the first key parameter based on the first session key to obtain a second dynamic identity and a second static public key; the server generates a third static public key based on the second dynamic identity; if the third static public key matches the second static public key, it is determined that the anti-quantum identity authentication of the server is successful; if the third static public key does not match the second static public key, it is determined that the anti-quantum identity authentication of the server fails. Through the technical scheme of the application, the calculation burden of the authentication process can be reduced, and the application is suitable for resource-limited devices.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

LLM protection through end-to-end crypto broadcasing protocols

In one aspect, a system is implemented for large language model (LLM) protection through end-to-end cryptography broadcasting protocols. The system uses an elliptic-curve cryptography (ECC) broadcast schema and post-quantum module lattice-based key encapsulation mechanism (ML-KEM) encapsulation for LLM file distribution. The system can include one or both of the client device(s) and cloud-based server(s) that communicate with each other for download of the LLM files to the client device(s).
Owner:LENOVO UNITED STATES INC

Encryption and decryption method and device for multi-modal data such as voice text

The invention relates to the technical field of information security, in particular to a voice text and other multi-mode data encryption and decryption method and device. The method comprises the following steps: decomposing a medical record containing multiple data types into independent composition modes; for each mode, using a unique and disposable symmetric key to encrypt large-volume data of the mode through a symmetric algorithm; defining an independent attribute-based access strategy for each mode, and encrypting a corresponding symmetric key by using a ciphertext strategy based on an attribute-based encryption scheme; and packaging the symmetric ciphertexts of all the modes and the corresponding encrypted symmetric keys into a structured multi-mode encryption container. The apparatus includes a plurality of functional modules for performing encryption and decryption steps. According to the scheme, the user can only decrypt the symmetric key corresponding to the data mode of which the authority meets the access strategy by virtue of the attribute private key, so that the problems of coarse access control granularity, high calculation overhead and easiness in leakage of strategy privacy in the prior art can be effectively solved.
Owner:MINIMALIST INTERNET (BEIJING) INFORMATION TECHNOLOGY CO LTD

A collaborative asset management system based on end-to-end encryption

This invention relates to the fields of information security and computer software technology, and discloses a collaborative asset management system based on end-to-end encryption, employing a zero-knowledge architecture with client-server collaboration. The client creates a collaborative space and generates a space key. For sensitive credentials, it generates a content key to form credential ciphertext and content key encapsulated ciphertext. During access, a controlled-use proxy decapsulates the content key encapsulated ciphertext in a local controlled execution environment to obtain the content key, completing controlled credential use and thus preventing the plaintext credential from being exposed to external programs. The server stores the space key encapsulated ciphertext, credential ciphertext, content key encapsulated ciphertext, and directory and policy information. Through a proxy re-encryption (ciphertext domain conversion) module, the space key encapsulated ciphertext is converted into ciphertext that new members can decapsulate without decrypting the plaintext key, enabling dynamic member addition without re-encrypting and retransmitting all credentials. The system registers capability declarations through extended module interfaces to describe heterogeneous asset access capabilities. Based on this, the client selects a connector and executes a blind injection / proxy call authentication process. At the same time, audit events are encrypted and their integrity is protected by hash chains or digital signatures. The server only stores audit ciphertext and non-sensitive index fields, thereby achieving collaborative management, controllable use, and scalable access under zero-knowledge conditions.
Owner:王华

Document sensitive fragment dynamic hierarchical encryption method based on content semantic features

The invention relates to a dynamic hierarchical encryption method for document sensitive fragments based on content semantic features. The method comprises the following steps: carrying out structured fragmentation modeling on to-be-protected document data to obtain sensitive fragment data and structure context data; performing multi-modal semantic representation construction on the sensitive fragment data and the structure context data to obtain content semantic representation data and irreversible semantic sketch ciphertext data; performing hierarchical state calculation on the content semantic representation data and the irreversible semantic sketch ciphertext data to obtain hierarchical state data; performing hierarchical binding double-layer envelope authentication encryption by combining the sensitive fragment data and the hierarchical state data to obtain fragment ciphertext data and key encapsulation ciphertext data; and carrying out encapsulation layer strategy rebinding updating on the fragment ciphertext data and the key encapsulation ciphertext data to obtain encrypted document data. By adopting the method, the security of the sensitive fragment of the document can be improved.
Owner:NANJING DAOCHENG NETWORK TECH CO LTD

A method of key encapsulation and encryption and decryption based on ntru lattice

The present application belongs to the technical field of lattice cryptography, and particularly relates to a key encapsulation and encryption / decryption method based on an NTRU lattice. The method comprises a public key encryption method and a key encapsulation method. The method is more compact and efficient, and only needs to change three parameters, i.e. ring dimension n, ring modulus q and ciphertext compression parameter d, when changing a parameter set. The key generation, encryption and decryption algorithm structure of the NTRU is simple, and only one polynomial multiplication is needed in the encryption / decryption process. The method has a shorter ciphertext length, does not need error correction code to compress the ciphertext, i.e. does not use error correction code to recover the plaintext, and has stronger security in both classical and quantum models.
Owner:SHANGHAI HONGGEHOU QUANTUM TECHNOLOGY CO LTD