Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

258 results about "Key exchange" patented technology

Key exchange (also key establishment) is a method in cryptography by which cryptographic keys are exchanged between two parties, allowing use of a cryptographic algorithm. If the sender and receiver wish to exchange encrypted messages, each must be equipped to encrypt messages to be sent and decrypt messages received. The nature of the equipping they require depends on the encryption technique they might use. If they use a code, both will require a copy of the same codebook. If they use a cipher, they will need appropriate keys. If the cipher is a symmetric key cipher, both will need a copy of the same key. If it is an asymmetric key cipher with the public/private key property, both will need the other's public key.

Internal and external network audio and video secure transmission method and system based on cloud platform

The invention relates to the technical field of audio and video transmission, in particular to an internal and external network audio and video secure transmission method and system based on a cloud platform. By combining the load balancing technology with the real-time load state and the audio and video stream characteristics of the cloud platform, the encrypted traffic can be dynamically distributed to a plurality of back-end servers, and the calculation overhead in the encryption process can be effectively reduced through selection of the lightweight asymmetric encryption algorithm and the optimized key exchange process; in a handshake stage, by optimizing a key negotiation process and adjusting a key exchange process according to segmentation characteristics, the execution efficiency of a protocol is further improved, and by dynamically adjusting the execution opportunity of encryption operation, it is ensured that the encryption operation is executed at a proper opportunity, and the encryption efficiency is improved. By monitoring and adjusting the load distribution strategy and the encryption parameters in real time, the system operation mode can be dynamically adjusted according to the distortion degree and the transmission state of the audio and video streams, and the distortion degree of the audio and video streams is effectively reduced.
Owner:HANGZHOU XUNCHUAN TECHNOLOGY CO LTD

Timing sequence post-synchronization quantum key extraction method based on classical information fusion

A time sequence post-synchronization quantum key extraction penetration test method comprises the following steps: A) under the condition of penetration test, a QKD system operates normally, and a sending end and a receiving end smoothly complete key distribution; b) the man-in-the-middle selects an initial original key exchange period to establish synchronization and correlation so as to realize clock synchronization with a receiver; c) analyzing quantum bit error rate information obtained from a public channel by a man-in-the-middle, deducing a corresponding relation between a receiver detector and each quantum state, and establishing a mapping model of the quantum states and bit values; d) determining a quantum state type responded by the receiver in each response time slot in a subsequent original key exchange period by the middleman in combination with path information obtained by other sub penetration tests; and E) the intermediary obtains a final key which is the same as the two communication parties by implementing an error correction and privacy amplification process, the quantum bit error rate between the intermediary and the sender is maintained at a relatively low level and is lower than a security threshold, and a security alarm is not triggered in a penetration test process.
Owner:NAT UNIV OF DEFENSE TECH

KEM-based anti-quantum TLCP protocol design method and system

The invention provides a KEM-based anti-quantum TLCP protocol design method and system, and belongs to the technical field of information security. The method comprises the steps that a server side applies for a server side signature certificate and an encryption certificate from an issuing mechanism, a long-term server side signature public key is stored in the server side signature certificate, and a long-term server side encryption public key is stored in the encryption certificate; and in the TLCP handshake protocol, identity authentication and key exchange between the server and the client are realized based on the long-term server signature public key and the long-term server encryption public key. According to the method, the anti-quantum KEM is used for replacing signature and encrypted primitives to realize key exchange and identity authentication functions of the protocol, identity authentication does not depend on the signature of a message any more, and meanwhile, a client introduces a temporary public key to replace a long-term static public key to participate in a KEM key negotiation process, so that the forward security of the protocol is ensured, and the security of the protocol is improved. Therefore, the efficiency and the security of the TLCP protocol are improved.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Server cipher machine communication method and system based on RDMA technology

The invention discloses a server cipher machine communication method and system based on an RDMA technology. According to the method, physical direct connection between a device end and an agent end is achieved by establishing an RDMA reliable connection channel; bidirectional authentication is carried out based on an SPDM protocol; a random challenge is generated after the device side verifies a proxy side certificate, and key exchange is triggered after a proxy side private key signature response and the verification of the device side are passed; the two parties adopt an SM2 public key algorithm to generate a shared key and derive a session key KEK; the proxy end encrypts the request data by using the KEK, and writes the encrypted data into the SMZ secure memory of the equipment end through the RDMA Write; the equipment end processes data through a hardware password engine, and directly writes an additional timestamp, a serial number and a result packet of MAC authentication to an appointed address of the agent end through RDMAWrite; and when the communication is finished, the device end erases the key and resets the engine. According to the invention, the problems of large delay, low throughput, low security, large CPU occupancy rate and the like in the prior art can be solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Access control authentication method based on multi-modal dynamic challenge and block chain auditing

The invention discloses an access control authentication method based on multi-modal dynamic challenge and block chain auditing, and belongs to the technical field of access control authentication, and the access control authentication method comprises the following steps: collecting video, sound and motion data of a user, and carrying out dynamic living body detection; after detection is passed, face features, voiceprint features and gait features are extracted and subjected to fusion scoring, and after the score exceeds a threshold value, equipment trust chain verification is carried out according to a dynamic token generated after secret key exchange between the APP and the access control terminal; after the verification is passed, firstly performing deep counterfeiting detection on the whole face, and then performing deep counterfeiting detection on the details of the face; and finally, the authentication passing information is stored in the block chain, TxID verification is carried out when a receipt of certificate storage transaction success returned by the block chain is received, and the door is authorized to be opened after the verification is successful. According to the invention, forgery attacks can be effectively resisted, the false identification rate and the missed identification rate of the access control system are reduced, the auditing tracking and tamper-proof capabilities are greatly enhanced, and the identity authentication reliability in a high-security scene is guaranteed.
Owner:NANJING INST OF TECH

Anti-quantum key packaging method and device, medium and equipment

The invention discloses an anti-quantum key packaging method and device, a medium and equipment, and the method comprises the steps that a first node generates a first public key and a first private key based on an asymmetric encryption algorithm, and generates a second public key and a second private key based on an anti-quantum encryption algorithm; sending the first public key and the second public key to a second node, so that the second node encrypts a third public key based on the second public key to obtain a public key ciphertext, and generates a shared key based on the first public key and a third private key; receiving a public key ciphertext sent by the second node, and decrypting the public key ciphertext based on the second private key to obtain a third public key; generating the shared key based on a third public key and the first private key; wherein the third public key and the third private key are generated by the second node based on an asymmetric encryption algorithm. According to the invention, by combining an anti-quantum encryption algorithm and a widely used asymmetric encryption algorithm, a secure key exchange mechanism which can resist future quantum computing threats and has high compatibility is provided.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Hybrid encryption method and device and storage medium

The invention provides a hybrid encryption method and device and a storage medium, and the method comprises the steps: a client generates a short-term SM2 key pair and exchanges with a server after obtaining a long-term SM2 key pair and a server public key, dynamically generates a session SM4 symmetric key through an SM2 key exchange protocol, and finally achieves the data transmission and response processing through the session SM4 symmetric key. Through the implementation of the scheme of the invention, the client not only establishes the basic trust relationship based on the long-term SM2 key pair, but also generates the short-term SM2 key pair during each service request, and dynamically derives a unique session SM4 symmetric key and an initial vector by cooperatively executing the SM2 key exchange protocol with the short-term key of the server. And each request has an independent security context, so that the decryption risk after the session key is reused or stolen is fundamentally prevented, and the end-to-end dynamic security communication under the national secret system is really realized.
Owner:SHANGHAI FEIWEI INFORMATION TECH CO LTD +2

Zero-trust gateway single packet authentication method and system for new energy fan control system, computing equipment, computer storage medium, computer program product and chip

The invention discloses a zero-trust gateway single packet authentication method and system for a new energy fan control system, computing equipment, a computer storage medium, a computer program product and a chip. The authentication method comprises the steps of generating an authentication material; exchanging and deriving a mixed key; binding Hash calculation is carried out; encrypting and assembling the message; receiving and verifying by the gateway; and binding verification and registration are carried out. The invention relates to a zero-trust gateway single packet authentication method combining a post quantum cryptography algorithm and a national commercial cryptography algorithm. The method is applied to secure communication between a wind power plant and a centralized control center, an SM2, SM3 and SM4 combined algorithm in a national secret system is combined with a post-quantum key agreement algorithm CRYSTALS-Kyber512, identity authentication, encryption and integrity verification are completed through a single message, confidentiality protection and anti-quantum security guarantee under one-time interaction are achieved, and the security of the wind power plant is improved. The method is especially suitable for new energy scenes with wide fan distribution, complex links and high real-time requirements.
Owner:DATANG HUAXIAN WIND POWER GENERATION CO LTD

Always Connected Drone Systems

A communication system is disclosed for maintaining persistent and secure wireless communication between a drone and a controller using an always connected mode. The drone operates as an 802.11 access point (AP), while the controller operates as a station (STA). During initial connection, the system performs a standard 802.11 association and key exchange, and stores the resulting association context, including the association response and encryption keys, to persistent memory. Upon detecting a disconnection or reboot, the system restores the saved context directly into the wireless driver to reinitialize MAC state and resume encrypted communication without repeating full association. The system includes modifications to wpa_supplicant, hostapd, and wireless drivers to support direct injection of association context and to temporarily disable replay protection. A dynamic switching mechanism selects between standard association and always connected mode based on runtime conditions such as link quality, proximity, or session validity.
Owner:SKYDIO INC

Private key full-life-cycle security management system and method based on mobile terminal anti-quantum cryptography algorithm

The invention provides a private key full-life-cycle security management system and method based on a mobile terminal anti-quantum cryptography algorithm. The method comprises the following steps: generating a key pair based on the anti-quantum cryptography algorithm; acquiring a certificate containing a public key in the key pair; calling a mobile terminal key management system to generate a symmetric encryption key, encrypting a private key in the key pair by using the symmetric encryption key, storing the encrypted private key into a sandbox, and storing a certificate into the sandbox; extracting a private key and a certificate in the encrypted key pair from the sandbox, calling the hardware-level key management system, and decrypting the private key by using the symmetric encryption key to obtain a decrypted private key; calling an interface matched with the purpose of the private key through a preset anti-quantum algorithm library, and executing signature, signature verification or key exchange operation by using the decrypted private key; and after the operation is completed, clearing the memory area for storing the private key plaintext. According to the method, the life cycle of the anti-quantum private key can be safely managed on the premise of not depending on the native support of a mobile system.
Owner:DONGFENG MOTOR GRP

Privacy protection federated learning method based on result-agnostic function encryption

The invention discloses a privacy protection federated learning method based on result-agnostic function encryption, and the method comprises the steps: dividing a derived key assembly into a plurality of shares, and carrying out the reconstruction through the remaining shares even if a part of clients are offline and the key shares are missing, thereby guaranteeing that a function key can be recovered, and an encryption model can be correctly aggregated, and improving the privacy protection efficiency. And the robustness and fault tolerance of the system are greatly improved. A non-interactive key exchange technology is adopted, and a secret sharing mechanism is combined, so that a client can generate a private key in a collaborative manner under the condition that no trusted third party participates, the deployment complexity is reduced, and the security and expandability of the system are improved. A function encryption process with an unknown result is designed, only an intermediate result in an encrypted state is output in an aggregation stage, and decryption is finally completed by local joint of a client, so that the possibility of snooping an aggregation result and reversely deducing original data by a server under a semi-honesty model is fundamentally avoided, and data privacy in a federated learning process can be effectively guaranteed.
Owner:SOUTH CHINA AGRICULTURAL UNIVERSITY

Electric power metering network security protection system and electric quantity acquisition data encryption transmission protocol

The invention provides an electric power metering network security protection system and an electric quantity acquisition data encryption transmission protocol used by the same. The system comprises a metering terminal, an edge gateway and a master station platform. The metering terminal is integrated with a domestic commercial password chip, adopts a three-level safety start chain and a data disturbance encryption mechanism, and has the functions of side channel protection and physical disassembly detection; the edge gateway constructs a multi-channel SM4 encryption assembly line based on the FPGA to realize encryption relay and data caching; the master station platform supports high-concurrency encryption session management, dynamic key updating and LSTM model driven abnormal traffic detection. The matched data encryption communication protocol is based on a state machine model and comprises the stages of time synchronization, key exchange, data transmission, integrity verification and the like. The system has high security, high real-time performance and strong environment adaptability, and is suitable for security access scenes of various power terminals such as intelligent electric meters, concentrators, micro-grid metering and the like.
Owner:MARKETING SERVICE CENT OF STATE GRID QINGHAI ELECTRIC POWER CO +1

Systems and methods for data lineage authentication

Systems, apparatuses, methods, and computer program products are disclosed for providing interoperability between private and public blockchains. An example method for providing interoperability between private and public blockchains includes, by a key exchange controller (KEC): receiving access key generation instructions; generating, based on the key generation instructions, an access key comprising access credentials; transmitting the access key to an access key target on a public blockchain network; receiving, from the access key target, a access request including the access credentials and information indicating a private blockchain on a private blockchain network; and providing, in response to receiving the access request, access for the access key target to access the private blockchain of the private blockchain network.
Owner:WELLS FARGO BANK NA

Systems and methods for data lineage authentication

Systems, apparatuses, methods, and computer program products are disclosed for providing interoperability between private and public blockchains. An example method for providing interoperability between private and public blockchains includes, by a key exchange controller (KEC): receiving access key generation instructions; generating, based on the key generation instructions, an access key comprising access credentials; transmitting the access key to an access key target on a public blockchain network; receiving, from the access key target, a access request including the access credentials and information indicating a private blockchain on a private blockchain network; and providing, in response to receiving the access request, access for the access key target to access the private blockchain of the private blockchain network.
Owner:WELLS FARGO BANK NA

Bluetooth communication method and system

A Bluetooth communication method implemented between first and second electronic devices, including establishing a communication in a connected mode between the first and second devices including a key exchange operation between these two devices, and establishing a communication in an advertising mode between the first and second devices including a periodic broadcast by the second device to the first device of a message including a payload and a calculated tag from this key.
Owner:EM MICROELECTRONIC-MARIN +1

Generating a secure key exchange authentication response using a security parameter index transform

Disclosed embodiments provide systems and methods for generating an SKE Authentication Response using a Security Parameter Index (SPI) Transform to provide secure data transfer in a computing environment. A disclosed method comprises receiving, from an initiator channel on an initiator node, a SKE Authentication Request message at a local key manager (LKM) executing a responder node to initiate a secure communication between the initiator channel and a responder channel. The LKM obtains a Security Parameter Index (SPI) Transform, an SA Index, and SPI Transform values. The LKM creates an SPI based on the SPI Transform using the SA Index and the SPI Transform values. The LKM builds an SKE Authentication Response message based on the SKE Authentication Request message and the SPI, which including the SPI and an encryption algorithm. The LKM transmits the SKE Authentication Response message to the initiator channel on the initiator node using the responder channel.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Third party based key exchange method, system and components thereof

The application provides a third-party-based key exchange method and system, a trusted third party and an entity, wherein the trusted third party only participates in identity authentication of the entity and assists in negotiation of a key between the two entities, and cannot obtain a shared key between the two entities, effectively solving the problem that the trusted third party cannot avoid obtaining the exchanged key in the existing key exchange scheme based on the trusted third party, and ensuring that the finally exchanged key is only owned by the two entities participating in the key exchange. In addition, in the application, the trusted third party can also provide a random number to participate in the final key generation, thereby ensuring the strength of the final key, meeting the requirement that the trusted third party needs to manage the strength of the exchanged key in a specific application scenario, and enhancing the management and control capability of the system.
Owner:QUANTUMCTEK CO LTD +1

Quantum key distribution protocol

A method for performing a quantum key distribution protocol among a first device, a second device, and an intermediary device (ID), the method including the ID transmitting a first secret symbol string to the first device via a quantum channel and a second secret symbol string to the second device via another quantum channel; the first and second devices demodulate their respective symbol strings and transmit reported symbol numbers to the ID; the ID shares basis state sets with both devices and generates a third symbol string by combining subsets of the first and second secret symbol strings corresponding to the reported symbol numbers; the ID transmits this third symbol string to the second device; and the first and second devices perform quantum key exchange by sifting validly received symbols in common positions.
Owner:ARQIT LTD

SM2-based proxy re-encryption algorithm implementation and file authorization sharing system

The invention discloses a system for realizing file authorization sharing based on an SM2 proxy re-encryption algorithm, and the system comprises a client module which is used for file encryption, key generation and key exchange between users; the server module is used for storing a file ciphertext and a Capsule and carrying out key conversion; and the encryption algorithm module is used for realizing secret key generation based on SM2, file encryption based on SM4 and Hash calculation of SHA3. The method has the beneficial effects that national commercial password standard algorithms such as SM2, SM4 and the like are fully fused, and data encryption and proxy re-encryption functions in a domestic algorithm environment are realized on the basis of ensuring the system security. As an elliptic curve public key cryptographic algorithm autonomously designed in China, the SM2 algorithm has the characteristics of public algorithm structure, high security, excellent calculation efficiency and the like.
Owner:内江数循数字科技有限公司

Systems and methods for a butterfly key exchange program

Embodiments described herein provide an implicit protocol with improved resource and bandwidth efficiency. A post-quantum secure approach for issuing multiple pseudonym certificates from a small piece of information is provided, while traditionally most encryption schemes are vulnerable to post-quantum attacks (e.g., in a traditional SCMS). Long-term security can be improved with the post-quantum protocol.
Owner:LG ELECTRONICS INC

A lightweight cross-domain identity authentication and key exchange method based on blockchain technology.

This invention discloses a lightweight cross-domain identity authentication and key negotiation method based on blockchain technology. First, a trusted consortium blockchain is established to ensure the trustworthiness of the root node certificate. Then, nodes within each domain broadcast their node identities using blockchain technology, obtain information through on-chain access, and achieve authentication and key negotiation with the help of trusted nodes. This method can resist various common attacks and meets security requirements such as authentication and key negotiation while protecting privacy. Designed to address the timeliness difficulties in cross-domain authentication in fields such as securities and finance, this solution avoids complex operations such as encryption / decryption and signature verification, using lightweight operations such as hashing and XOR. It can be applied in fields such as finance, banking, transportation, education, government affairs, and healthcare, improving the security and efficiency of cross-domain access.
Owner:BEIJING SANSEC TECH DEV

Key cooperative exchange method and device, electronic equipment and medium

This application discloses a method, apparatus, electronic device, and medium for collaborative key exchange. In this application, upon receiving a peer random number public key from a peer key device, the peer random number public key and a first random number public key are sent to a second communicating party. The first random number public key is calculated by the first communicating party using an elliptic curve cryptography algorithm. The second communicating party calculates its own random number public key based on the peer random number public key, the first random number public key, and a second sub-private key, and then sends its own random number public key and intermediate parameters to the first communicating party. The first communicating party calculates a shared key based on its own random number public key, intermediate parameters, and the first sub-private key, and then sends its own random number public key to the peer key device.
Owner:BEIJING WATCH DATA SYSTEM CO LTD

Key exchange system, server, method, and non-transitory computer-readable recording medium storing program for deploying an intermediate server between the key generation device and the network device

According to an embodiment, a key exchange system includes: a key generation device configured to generate a key based on quantum key exchange or post-quantum key exchange; a network device configured to perform encrypted communication with another network device by using the key; and an intermediate server deployed between the key generation device and the network device. The intermediate server includes: a state monitoring unit configured to transmit a state monitoring request to the key generation device at each predetermined time; a notification unit configured to give a push notification of key information included in a response to the state monitoring request, to the network device, when the response is received; and a key exchange unit configured to start key exchange between the network device and the key generation device in response to a request from the network device having received the push notification of the key information.
Owner:NT T INC

A key exchange method, apparatus, device, and storage medium

The application discloses a key exchange method and device, equipment and storage medium, and relates to the technical field of information security, and comprises the following steps: constructing a notification message and sending the notification message to a message responder, so that the message responder returns a response message according to the notification message; constructing a first post-quantum key exchange notification and sending the first post-quantum key exchange notification to the message responder, so that the message responder constructs a first key exchange response and sends the first key exchange response to the message initiator; generating a first post-quantum signature result, and constructing a second post-quantum key exchange notification and sending the second post-quantum key exchange notification to the message responder, so that the message responder receives the second post-quantum key exchange notification, generates a second post-quantum key ciphertext, and constructs a second key exchange response and sends the second key exchange response to the message initiator; and performing identity authentication between the message initiator and the message responder. The application realizes quantum security of key exchange by constructing a post-quantum key exchange notification by using a post-quantum public key algorithm, and realizes key exchange and identity authentication between the message initiator and the message responder.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

Computational function transformation (CFT) in computer implemented cryptography

Data is processed by cryptographic operations selected from encryption, decryption, hashing, and public key exchange (PKI). Data elements are processed as n-state data elements with n an integer at least greater than 3 based on an n-state reversible n-state inverter. The n-state reversible inverter is a self-propagating n-state inverter generating different other n-state reversible inverters. The n-state reversible inverter is derived from a sequence of n n-state data elements with at least a first n-state data element occurring at least twice in different positions in the sequence and a second n-state data element not occurring. The n-state reversible inverter is created from the sequence of n-state data elements. A sequence of n n-state elements is created from a set of k n-state elements with k smaller than n. The k n-state elements are provided by a public key exchange method.
Owner:LABLANS PETER MR

Method, equipment, device and medium for passive optical network activation

The embodiment of the invention relates to a passive optical network activation method, equipment, a device and a medium. In accordance with an example embodiment of the present disclosure, a first device receives a key control message from a second device during a key exchange. The key control message instructs the first device to generate and transmit a key by using an encryption algorithm to be used, or to confirm a key corresponding to a currently used encryption algorithm. The key control message also instructs the first device to generate a key report based on the key control message, and to send the key report to the second device. In this way, the secret key and the encryption algorithm in the communication process of the first device and the second device can be matched, and the stability of channel work is improved.
Owner:ALCATEL LUCENT SHANGHAI BELL CO LTD +1

Autonomously booting system with encryption of the entire data storage and method for this

Encryption system with an application-specific integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the operating system (OS) of a processor and software modules for encrypting the data memory of the processor and which has a hardware-implemented encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous booting of the operating system (OS), consisting of: - a symmetric cryptosystem (SK) for processing symmetric keys, - an asymmetric cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented key exchange protocols (SP), - a key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a central processing unit (CPU) via a communication interface (CS1), and that the central processing unit (CPU) communicates with at least one internal storage (IS) and one external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.
Owner:IAD GESELLSCHAFT FUER INFORMATIK AUTOMATISIERUNG & DATENVERARBEITUNG MBH

Lightweight identity authentication method for limited equipment under power internet of things

The invention relates to the field of security protection of the electric power Internet of Things, in particular to a lightweight identity authentication method for limited equipment under the electric power Internet of Things, which can adapt to a large-scale and widely distributed network environment of the electric power Internet of Things by introducing a lightweight encryption algorithm and an efficient key exchange protocol, ensures the security, and improves the authentication efficiency of the limited equipment under the electric power Internet of Things. The calculation burden and the energy consumption of limited equipment in the power Internet of Things are effectively reduced; a decentralized authentication mechanism is adopted, so that the problems of single-point failure and performance bottleneck in a traditional centralized authentication method are solved, efficient equipment authentication and key exchange are realized, and the expandability of a network is ensured; security threats such as replay attacks and man-in-the-middle attacks are effectively prevented by periodically updating session keys and using digital signatures, and the reliability of network communication and the confidentiality of data are enhanced. By introducing a key exchange protocol and a digital signature technology, the integrity and authenticity of data are guaranteed, tampering behaviors of malicious nodes are prevented, and the overall security of the system is improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD +3