Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Key escrow" patented technology

Key escrow (also known as a “fair” cryptosystem) is an arrangement in which the keys needed to decrypt encrypted data are held in escrow so that, under certain circumstances, an authorized third party may gain access to those keys. These third parties may include businesses, who may want access to employees' private communications, or governments, who may wish to be able to view the contents of encrypted communications.

Data security protection method, device and system based on anti-quantum cryptography algorithm

The invention provides a data security protection method, device and system based on an anti-quantum cryptography algorithm, and the method comprises the steps: setting a security storage agent node, enabling the security storage agent node to divide original data into hot data or cold data according to the security level of the original data and access data, the hot data and the cold data are encrypted by adopting different encryption modes, so that the data processing performance is optimized under the condition of ensuring the data security; besides, the data encryption key is subjected to fragmentation encryption, a separated secure storage mode is adopted, the traditional key trusteeship single-point risk is broken through, the data security is further improved, the data encryption key is subjected to fragmentation encryption by adopting a post-quantum encryption algorithm, quantum attack can be effectively resisted, and long-term data security can be guaranteed.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Internet of vehicles cross-domain identity authentication method based on PUF (Physical Unclonable Function) and certificateless

The invention provides an Internet of Vehicles cross-domain identity authentication method based on PUF and certificateless, and the method comprises the steps: firstly generating a system master key and a master public key through a KGC, and disclosing system parameters; secondly, the vehicle generates a physical response and extracts a stable key, interacts with the KGC to complete generation of a certificateless key pair, and stores registration information to a block chain; then the edge server registers in the KGC, obtains a certificateless key pair, initiates an authentication request to the KGC, and obtains a block chain data reading authority; finally, bidirectional authentication is carried out between the vehicle and the edge server based on the certificateless signature and the PUF response, and a session key is generated; and the cross-domain vehicles are assisted by the edge server to complete mutual identity authentication and session key negotiation. According to the method, the key escrow and certificate management burden is eliminated by adopting a certificateless cryptosystem, the high computing load is released to the edge server in combination with the PUF hardware security characteristic and the block chain distributed trust, the computing and communication overhead is remarkably reduced, and the method is suitable for a large-scale Internet of Vehicles cross-domain authentication scene.
Owner:GUIZHOU UNIV

Internet of vehicles data sharing method based on cloud

The invention discloses a cloud-based Internet of Vehicles data sharing method, which comprises the following steps that: under a certificateless framework, a secret key generation center distributes part of private keys, and a user combines local secret key values into a complete private key; a data owner encrypts and uploads traffic data based on bilinear mapping, and then constructs a re-encryption key through polynomial interpolation, so that a cloud server can decrypt all receivers in an authorization set through one-time re-encryption, and meanwhile, the identities of the receivers are hidden. Timestamp embedding achieves temporary entrustment, and the cloud does not make contact with plaintexts and private keys in the whole process. According to the scheme, key escrow is eliminated, terminal communication calculation overhead is reduced, and anonymous, fine-grained and time-efficient data sharing requirements of the Internet of Vehicles are met.
Owner:JIANGSU UNIV OF TECH

Decentralized Local Accountless Authorization Gateway for Continuity-Based Service Access Across Heterogeneous User-Interface Nodes

PendingUS20260254877A1EngineeringKey escrow
A decentralized authorization system enables continuity-based service access using a continuity anchor device that derives non-invertible continuity tokens from biometric or interaction-derived signals combined with a device-specific secret value. The anchor device generates local authorization requests referencing cryptographic derivatives of the continuity token, validates cryptographic receipts or zero-knowledge proofs using locally stored cryptographic key material, and updates a local time-locked authorization register without requiring persistent user accounts, remote account login, cloud-hosted entitlement validation, or external key escrow. Service access parameters include session duration, memory depth, and cross-device restoration privileges. A similarity metric is evaluated locally at the continuity anchor device prior to authorizing session context restoration. Any remote account login or cloud-hosted entitlement validation is insufficient by itself to authorize service access absent local validation within the continuity anchor device. The system supports offline operation and policy-adaptive compliance modes.
Owner:BRACKEN ALEXANDER JOHN

An encryption method based on registration keyword strategy hiding

This invention provides a searchable encryption method based on registered keywords and with hidden policies, belonging to the field of cryptography and information security technology. It solves the risks of key escrow and keyword privacy leakage in existing attribute-based search encryption schemes. The technical solution includes the following steps: S1, system initialization; S2, user key generation; S3, user public key validity detection; S4, generation of the system master public key; S5, trapdoor generation; S6, keywords for the encryption access policy; S7, keyword policy detection. This invention utilizes a set of arithmetic and non-double number sequences to construct system common parameters, shortening the parameter length. Simultaneously, it employs a dual-system encryption mechanism to achieve complete security and hides the keyword policy by embedding subgroup elements in the ciphertext, thereby ensuring keyword privacy. While ensuring data confidentiality, this method enables secure and flexible retrieval of encrypted data.
Owner:NANTONG UNIV

Private data protection method and device, equipment, medium and program product

The present disclosure relates to a privacy data protection method, apparatus, device, medium and program product, and relates to the technical field of information security, the method comprising: a group agent node receiving an encrypted data packet sent by a first user, the encrypted data packet comprising a first ciphertext, the first ciphertext is obtained by encrypting private data and signature data of the private data by the first user through a first private key; and re-encrypting the first ciphertext into a second ciphertext through a re-encryption key, so that a second user uses a second private key to extract private data from the second ciphertext, and the re-encryption key is generated by the first user based on the first private key, the second public key and the proxy re-encryption system parameters. The privacy data protection method and device can solve the problem of privacy data leakage caused by key escrow risk, plaintext leakage risk and the like existing in a current privacy data protection scheme.
Owner:SHENHUA HOLLYSYS INFORMATION TECH CO LTD

Certificate signing scheme based on SM9 signature algorithm

ActiveCN115589296BID-based encryptionKey (cryptography)
The application is suitable for the field of information security technology, and provides a certificate signature scheme based on an SM9 signature algorithm, which comprises the following steps: S100, system initialization calculation, a certificate authority generates a random number as a private key and calculates a public key, then randomly selects a signer private key and performs public key calculation to produce a signer private key pair; S200, certificate authorization, a signer provides identity information to the certificate authority, the certificate authority verifies the information according to the information and the key information, and calculates and generates a certificate after the information passes, and feeds back the certificate to the signer; and S300, signature calculation and the like. The application is based on the signature structure of the SM9 national secret algorithm, combines the advantages of traditional public key cryptography and identity-based encryption technology, and solves the problems of complex certificate management and key escrow. The scheme can resist attacks of Type 1 and Type 2 enemies at the same time.
Owner:SHANGHAI MATRIXELEMENTS TECH CO LTD +1

A traditional chinese medicine data sharing method based on attribute-based encryption and homomorphic encryption

This invention proposes a method for sharing traditional Chinese medicine (TCM) data based on attribute-based encryption and homomorphic encryption. The method includes an attribute authorization agency, TCM data owners, a blockchain, TCM data users, data user agents, and private key sharers. The attribute authorization agency is responsible for generating the homomorphic encryption public and private keys, attribute public and private keys, and verifying data compliance. The data owner encrypts the data using the homomorphic encryption public key and stores it on the blockchain after setting access policies using attribute-based encryption. When a data user initiates an access request, the data user agent verifies the user's access rights. Upon successful verification, a homomorphic operation is performed on the ciphertext. Subsequently, multiple private key sharers, who collaboratively manage fragments of the homomorphic private key, complete partial decryption. Finally, the TCM data user recovers the plaintext result. This method ensures that TCM data is usable but not visible through homomorphic encryption, achieves precise access control through attribute-based encryption, and reduces the risk of private key escrow through secret sharing.
Owner:XIAN MEDICAL UNIV

A blockchain-based distributed key escrow method

The application discloses a kind of distributed key escrow methods based on block chain, there are two kinds of committee identity nodes in the method: escrow node and election node. The secret is fragmented using improved Shamir secret sharing, and the fragmented fragments are escrowed on anonymous escrow nodes, which are dynamically elected by the election nodes. The election committee builds an anonymous communication channel to maintain the anonymous identity of the escrow committee. Every certain period of time, the smart contract triggers the re-election of the election nodes and the escrow nodes, dynamically changing the membership of the committee. The old escrow nodes transfer the fragmented shares to the new escrow nodes by halving the fragmented shares through anonymous communication, and the new escrow nodes restore the fragmented shares after receiving them, completing the regular dynamic update of the escrow nodes. The application ensures the security, anonymity and tamper resistance of node information, and decentralizes the management of keys, improving the security and reliability of secret escrow.
Owner:ZHEJIANG UNIV

Data electronic fence processing system and method based on attribute encryption and block chain

The invention relates to a data electronic fence method and system based on attribute encryption and a block chain. Comprising the following steps: designing a multi-authorization-based key generation method, and solving the problems of key escrow and single-point fault existing in a single authorization center; an efficient attribute revocation mechanism based on the smart contract is constructed, a hash value of an attribute key of the latest version of a data user is used as a pass, the access decision contract completes automatic verification of identity and access authority, and user attribute revocation can be realized only by updating the attribute key; a strategy updating mechanism which is low in calculation cost and combined with the block chain technology is built, when a service requires to update an access strategy, the symmetric key is re-encrypted according to the symmetric key index stored on the chain and a new access strategy, and the access permission is judged in combination with an access decision contract; and the block chain technology is combined to realize data sharing full-process credible evidence storage such as data resource release, data request access, data transmission, data acquisition, attribute revocation and strategy update.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Data security protection method, device and system based on anti-quantum cryptography algorithm

This application provides a data security protection method, device, and system based on quantum-resistant cryptographic algorithms. By setting up secure storage proxy nodes, the secure storage proxy nodes divide the original data into hot data or cold data according to the security level of the original data and the access data, and encrypt the hot data and cold data respectively using different encryption methods, thereby optimizing data processing performance while ensuring data security. In addition, by encrypting the data encryption key in fragments and adopting a separate secure storage method, the single point of failure risk of traditional "key escrow" is overcome, further improving data security. By using post-quantum encryption algorithms to encrypt the data encryption key in fragments, effective resistance to quantum attacks can be achieved, ensuring long-term data security.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Key escrow method, device and equipment based on SIM (Subscriber Identity Module) card, medium and program product

The invention discloses a secret key escrow method and device based on an SIM card, equipment, a medium and a program product, and relates to the technical field of identity authentication, and the method applied to terminal equipment comprises the following steps: sending a first request to a TSM platform, receiving a first instruction, and installing a first escrow application in a first SIM card in the terminal equipment based on the first instruction; obtaining a master key pair generated based on the first hosting application, and sending first information to the TSM platform; sending a second request to an identity service platform pre-accessed by the business application program APP, receiving a DID sent by the identity service platform in response to the second request, and sending the DID to the TSM platform; the second request carries a public key in the master key pair, and the DID is generated by the identity service platform based on the public key in the master key pair; under the condition that the first SIM card is replaced by the second SIM card, sending a third request to the TSM platform, and receiving a DID and hosting information sent by the TSM platform; and writing a master key pair corresponding to the DID and the first information into the second SIM card.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

PUF (Physical Unclonable Function)-based certificateless proxy signature smart grid distributed energy transaction method

The invention relates to the technical field of smart power grids and information security, in particular to a PUF (Physical Unclonable Function)-based certificateless proxy signature smart power grid distributed energy transaction method, which comprises the following steps of: constructing a PUF-based certificateless proxy signature smart power grid distributed energy transaction system, transaction is carried out based on the certificateless proxy signature smart power grid distributed energy transaction system; the system comprises a power grid operator, an energy manufacturer, an agent, PUF equipment and a block chain, the transaction process comprises an initialization stage, an identity authentication stage and a transaction stage; according to the method, the unique key of the equipment is generated through the PUF, the problems of complex certificate management and key escrow are avoided by adopting a certificateless mechanism, decentralized evidence storage and non-tampering of transaction data are ensured based on the block chain, the problems of insufficient security, low efficiency and weak anti-attack ability of a traditional scheme can be effectively solved, and the method is adaptive to the resource-limited Internet of Things equipment and has the advantages of high security and high reliability. And efficient and credible safety guarantee is provided for distributed energy transaction of the smart power grid.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Threshold key escrow and member update method and device based on a blockchain system

The application discloses a threshold key escrow and member updating method and device based on a blockchain system, relates to the field of combination of blockchain and cryptography, determines a group public key and a private key of a Paillier encryption scheme, and performs threshold share allocation work on the private key of the Paillier encryption scheme according to the number of members in a committee, so that the escrow share of the threshold Paillier private key share of each member after an encryption operation can be placed on the blockchain system; when a member in the committee exits, a threshold Paillier decryption operation and a Lagrange reconstruction method are used to determine the threshold Paillier private key share of a new member and perform an escrow operation. The application can improve the security and convenient operability of the whole key escrow scheme.
Owner:BEIHANG UNIV +1

Certificateless key negotiation method and system supporting public key check and application

The invention relates to the field of electric power information network and data security, in particular to a certificateless key negotiation method and system supporting public key check and application, and the method comprises the steps: initializing a key generation center, outputting public parameters, constructing a revocation system based on an accumulator, and outputting revocation state parameters; the user sequentially generates a user private key and a user public key based on the public parameter, and sends the user public key to the key generation center, so that the key generation center returns part of the private key and part of the public key, accumulates the user to an accumulator, and updates the revocation state parameter; according to the invention, the revocation state of the user can be checked, the user generates the user key in the key generation process, and the key generation center only generates a part of keys, so that the problem of key escrow is solved, and the security of the user is improved. And the safety and light weight of the system are ensured.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +4

Certificateless weighted multi-identity cross-domain authentication scheme combined with block chain

The invention discloses a certificateless weighted multi-identity cross-domain authentication scheme combined with a block chain, and aims to solve the problem that the existing related technology is difficult to adapt to diversified authentication of a complex Internet of Things environment. According to the method, a certificateless weighted cross-domain authentication scheme is designed by considering the multi-identity characteristics of cross-domain users and the credible weight difference of different identities. According to the scheme, a distributed block chain structure is adopted, and the non-tampering performance and the synchronization reliability of parameters are guaranteed; through cooperation of a threshold signature algorithm and a certificateless signature algorithm, the overall security of the system is maintained, and the third-party key escrow risk is thoroughly avoided. Besides, the digital signature protocol integrated with the identity weight is designed to realize differential authentication, the user with higher credible weight only needs less part of identity information to complete authentication of the user with low weight, and the efficiency is greatly improved. According to the invention, the security, reliability and flexibility of cross-domain authentication are enhanced, specific scene requirements of the Internet of Things are adapted, and an efficient solution is provided.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY

On-lattice certificateless ring type collaborative signature method and system

The invention provides an on-lattice certificateless ring type collaborative signature method and system, and relates to the technical field of quantum communication. The method comprises the following steps: a key generation center generates a public and private key pair according to system parameters, and the key generation center generates a public and private key pair of each ring member end based on the system parameters, the public and private key pair, identity information of each ring member end and an auxiliary private key sent by each ring member end, a key generation center generates a complete key for a ring member end based on identity information of the ring member end and an auxiliary private key sent by the ring member end, so that the malicious KGC is prevented from abusing the key or implementing a key escrow attack, and key escrow risks and quantum computing attacks are effectively prevented; the signer side can generate the ring-type collaborative signature by using a private key of the signer side and public keys of other ring member sides in the ring, so that the privacy protection of the user is enhanced; and the verifier side uses the main public key and the target public keys of all the ring member sides to carry out validity verification on the ring-type collaborative signature to obtain a signature verification result.
Owner:中电信量子信息科技集团有限公司

Distributed identity-based encryption against key leakage

The application discloses a kind of anti-key leakage distributed identity-based encryption method, by system initialization, key generation, key update, encryption, decryption step composition.In the key generation step, for the key escrow problem in identity-based encryption mechanism, the decryption key is calculated for user by distributed key generation technology, the privacy of user key is guaranteed, the problem that the right of key generation center is too large in traditional identity-based encryption is solved.In the key update step, by re-randomizing to the original key of user, the entropy loss of key caused by information leakage is filled, and the security and practicability of the scheme under continuous leakage attack are guaranteed.In the encryption step, by introducing the legality verification element of ciphertext, the ciphertext is not extensible, so that the scheme has the security of resisting selected ciphertext.The method of the application adopts anti-leakage cryptography mechanism and distributed key generation technology, and proposes a practical identity-based encryption scheme, which can be used in the field of access control technology.
Owner:SHAANXI NORMAL UNIV

A double random number based key escrow method

The application discloses a kind of key escrow methods based on double random number, it is related to information security technical field, including: by user identity information authentication and living body identification, generate double random number;According to the double random number and PIN code input by user, calculate and generate key pair, then, to key escrow service application user equipment certificate and signature key, key escrow service uses user equipment certificate to generate key pair, encrypts signature key to obtain key ciphertext, and user equipment certificate and key ciphertext are stored in cloud;When user requests authorization to use signature key, check random number consistency, signature validity, and after check passes, key escrow service uses signature key to process data to be signed and returns result;Key escrow service uses newly generated key pair to encrypt signature key to obtain new key ciphertext, and new key ciphertext is stored in cloud.The application can guarantee that signature is not repudiable, integrity, legality and security.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

A secure and efficient and lightweight adsb system certificateless signature scheme

The application discloses a safe, efficient and lightweight certificateless signature scheme of ADS-B system, which comprises the following steps: generating system parameters by a key generation center KGC and publishing the system parameters to the ADS-B system; acquiring real identity information of a signer by the key generation center KGC and returning a partial private key; calculating a complete private key of the signer based on the partial private key and a selected secret value, deriving a public key based on the complete private key and publishing the public key to the ADS-B system for public; and broadcasting the message information signed by the signer. The application gives a specific signature position design according to the message field, does not need complex certificate management, and only generates a partial private key by the KGC to avoid the key escrow problem, so that the application is more flexible and scalable in large-scale deployment. Compared with a general bilinear scheme, the application has low calculation complexity, supports batch verification, improves the authentication efficiency of the system and is suitable for the aviation communication environment with limited resources.
Owner:BEIHANG UNIV

Blockchain-based decentralized archive data security management method and system

The application relates to the technical field of data security, in particular to a decentralized archive data security management method and system based on a block chain, which comprises the following steps: based on a Fabric alliance chain, constructing an archiving node, an access node, an approval node and a supervision node; when uploading archive data, the archiving node encrypts the archive data by using an encryption algorithm, and sends an encryption key to the supervision node, the encryption key being used for decrypting the archive data; when requesting to access the archive data, the access node sends an access request to the approval node; if there is access permission, the approval node sends a decryption request to the supervision node; and the approval node sends a download request to the archiving node. The archive encryption processing guarantees the confidentiality of data, even if the data in the database is read, the original information cannot be interpreted; the key hosting and operation record chaining of the supervision node ensure that the archive use process is auditable and tamper-proof.
Owner:XINJI INFORMATION TECH GRP CO LTD

Trusted computing-based local key escrow method, apparatus, device and medium

This application provides a trusted computing-based local key escrow method, apparatus, device and medium. The method includes: determining an executable file associated with an untrusted environment and a dynamic link file associated with a trusted environment in response to acquiring an enclave interface definition file from a local internal memory; determining an environment access interface based on a container identifier indicated by the trusted environment in response to loading the dynamic link file based on the executable file; reading sealed data file obtained by encrypting serialized data based on a local key in the untrusted environment in response to accessing an enclave container in the trusted environment through the environment access interface; and decrypting the sealed data file using the local key and deserializing the decrypted sealed data file in the enclave container to obtain service data for loading into a trusted internal memory indicated by the enclave container.
Owner:TENCENT CLOUD COMPUTING (BEIJING) CO LTD

Smart grid terminal group secure communication method and device based on certificateless public key cryptography

The invention relates to the technical field of network security and cryptography, and discloses an intelligent power grid terminal group security communication method and device based on certificateless public key cryptography, comprising three stages of system initialization and registration, key negotiation and communication, and fault self-healing. A key generation center constructs certificateless public key cryptosystem parameters of elliptic curve cryptography, a security gateway carries out offline registration, an intelligent terminal carries out broadcast registration and is arbitrated and taken over by an intra-group gateway, and encryption communication of a management-gateway layer, a gateway terminal layer and a group broadcast layer is realized by adopting a layered key negotiation architecture. A gateway fault self-healing mechanism of heartbeat detection and arbitration takeover is designed, and meanwhile, a device for realizing the method is matched. Certificate management and key escrow risks are eliminated, the lightweight operation requirement of the terminal is adapted, terminal dynamic registration and gateway fault self-recovery are realized, the broadcast communication efficiency is improved, high communication security, high availability and high efficiency are considered, and the method is suitable for a large-scale smart grid terminal group security communication scene.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +1

Systems and methods for blockchain-based secure key exchange with key escrow fallback

A system described herein provides for the secure maintaining and providing of information, such as public keys used in Public Key Infrastructure (“PKI”) techniques or other techniques, using a distributed ledger (e.g., “blockchain”) system with a fallback to a key escrow system. A first device may encrypt a communication using a first key, and output the encrypted communication to a second device. The first device may attempt to record a second key, that is associated with the first key, to the blockchain system, and may determine that the second key was not recorded to the blockchain system based on the attempt. The first device may output the second key to a third device based on determining that the second key was not recorded to the blockchain system. The second device may obtain the second key from the third device, and use the second key to decrypt the encrypted communication.
Owner:VERIZON PATENT & LICENSING INC

Hierarchical ciphertext storage and self-adaptive decryption method carrying algorithm identifier

The invention discloses a hierarchical ciphertext storage and self-adaptive decryption method carrying algorithm identification. A write-in side firstly processes data to be protected according to a target algorithm to obtain a load, generates a self-description structure containing an algorithm category, a number, a version and a parameter reference identifier, and then performs outer layer unified encryption on the structure to form a layered ciphertext and stores the layered ciphertext. Reading an analysis algorithm identifier after side de-encapsulation, automatically shunting into an abstract verification or reversible decryption path, and obtaining a key and a salt value according to parameter reference to complete verification or decryption; and when a historical version or an old format is detected, compatible processing is executed according to version mapping or a preset rule. According to the method, dependence on external configuration is eliminated, unreadability caused by loss of algorithm identifiers is avoided, algorithm information is reinforced and hidden on the outer layer, key escrow and rotation are supported, online and offline processing links are unified, the operation and maintenance cost is reduced, and the method is suitable for sensitive data protection of databases, object storage and file storage.
Owner:HANGZHOU ARTECH

Key generation method and system, electronic equipment and storage medium

The embodiment of the invention provides a key generation method and system, electronic equipment and a storage medium. The method comprises the following steps: enabling a client to generate a complete user private key d A1 according to a user part private key t A1 and a temporary user private key d A1, and determining a user part public key P A1 based on a first part public key W A1 and a main public key Ppub; and sending the second part public key W A2 and the server part private key t A2 to the server, so that the server generates a complete server private key d A2 according to the server part private key t A2 and the temporary server private key d A2, and determines the server part public key P A2 based on the second part public key W A2 and the main public key Ppub. According to the scheme, the key trusteeship problem of the key generation center can be fundamentally solved, and the security is relatively high.
Owner:BEIJING INFOSEC TECH CO LTD +1

Data processing method and device based on trusted execution environment, equipment and medium

The application provides a data processing method and device based on a trusted execution environment, equipment and a medium. The method comprises the following steps: when a resource management client successfully remotely authenticates a key management client, object data encryption information encrypted based on a first communication key and a to-be-signed transaction are sent to the key management client, so that the key management client remotely signs the to-be-signed transaction by using a managed key fragment when object access data information is decrypted based on the first communication key; when transaction remote signature information returned by the key management client is received, the to-be-signed transaction is locally signed by using a first key fragment decrypted based on the object access data information, to obtain transaction local signature information; and the to-be-signed transaction is written into a blockchain based on the transaction remote signature information and the transaction local signature information. By using the application, the security of key storage and the reliability of transaction chaining can be ensured.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Attribute hiding disclosure and on-chain verification system based on zero-knowledge proof

The invention discloses an attribute hiding disclosure and on-chain verification system based on zero knowledge proof, comprising a client layer responsible for user attribute management, proof strategy configuration and local proof generation; the under-chain certification layer is used for reducing the certification generation cost and improving the system expansibility, and the under-chain certification layer transmits the aggregation certification to the block chain layer; the block chain layer receives the aggregation proof and verifies the aggregation proof, and meanwhile, the credibility and interoperability of a verification result are ensured; the supervision layer is used for protecting the privacy of the user and meeting the supervision requirement at the same time; the application layer provides a standardized API interface and supports access of various application scenes. According to the method, the minimum disclosure of the attributes is realized, and the user privacy is protected to the greatest extent; through an under-chain distributed proof generation and recursive aggregation technology, the calculation complexity and cost of on-chain verification are greatly reduced; through threshold key escrow and selective gateway disclosure, the balance between privacy protection and supervision compliance is realized.
Owner:BEIJING LIANDING TECHNOLOGY CO LTD

Lightweight certificateless authentication method based on double-layer threshold

The invention discloses a lightweight certificateless authentication scheme based on a double-layer threshold, and relates to the technical field of information security. The scheme aims to solve the problems of single-point failure of a key generation center and low key escrow and authentication efficiency in a certificateless system. According to the method, firstly, a decentralized key management mechanism is provided, a non-homogeneous double-variant polynomial is utilized to construct a double-layer threshold architecture of transverse node cooperation and longitudinal key synthesis, safe distribution and reconstruction of a main key and a private key are achieved, and the attack resistance and robustness of the key generation process are improved. On this basis, a lightweight anonymous authentication protocol is designed, a dynamic pseudo identity is generated through a random number to resist identity association attacks, and linear operation is adopted to replace bilinear pairing operation. The method is mainly used in a distributed network environment, reduces the calculation overhead while guaranteeing the privacy and anti-aggressiveness of the user, and improves the overall performance of an authentication system.
Owner:CHONGQING UNIV OF POSTS & TELECOMM