Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

360 results about "Key exchange" patented technology

Key exchange (also key establishment) is a method in cryptography by which cryptographic keys are exchanged between two parties, allowing use of a cryptographic algorithm. If the sender and receiver wish to exchange encrypted messages, each must be equipped to encrypt messages to be sent and decrypt messages received. The nature of the equipping they require depends on the encryption technique they might use. If they use a code, both will require a copy of the same codebook. If they use a cipher, they will need appropriate keys. If the cipher is a symmetric key cipher, both will need a copy of the same key. If it is an asymmetric key cipher with the public/private key property, both will need the other's public key.

High-security method for negotiating temporary session key based on national secret algorithm

The invention relates to the technical field of commercial password detection methods, and discloses a high-security method for negotiating a temporary session key based on a national secret algorithm, and the commercial password detection method comprises the following steps: initialization and identity authentication: two communication parties generate an SM2 public and private key pair, and the identity is verified through a digital certificate and an SM2 signature; temporary key negotiation: generating a shared key point based on an SM2 key exchange protocol; session key derivation: generating a temporary session key by using an SM3 hash algorithm; key confirmation and encrypted communication: verifying the key through an SM4 algorithm and encrypting communication data; according to the high-security method for negotiating the temporary session key based on the national secret algorithm, efficient key negotiation of both communication parties in an unsecure channel is realized through an SM2 key exchange protocol, an SM3 hash algorithm and an SM4 symmetric encryption algorithm. The method combines digital certificate authentication, dynamic random numbers and timestamps, has forward security, replay attack resistance and man-in-the-middle attack resistance, and is suitable for high-security scenes such as finance and government affairs.
Owner:SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD

Communication protocol security verification method based on quantum key distribution

The invention relates to the technical field of quantum key distribution, and discloses a communication protocol security verification method based on quantum key distribution, which comprises the following steps of: establishing a quantum communication channel framework, loading protocol parameters to generate an initial security verification model, configuring a security state transition rule, and performing cross-layer data fusion in combination with quantum entity parameters; and obtaining a whole-process safety tracking model. And executing security path deduction through the model, generating a key exchange trajectory chain, constructing security trajectory simulation data, establishing a quantum conflict resolution mechanism, training and generating a security policy optimization model, and outputting security governance parameters. Security increment simulation information is generated based on security governance parameters and the like, a multi-target decision model is constructed in combination with protocol evolution constraint conditions, optimal security path parameters are adjusted and generated, a security verification strategy is verified and updated through a real-time quantum mapping network, and a whole-process security matching target is achieved. According to the method, the comprehensiveness, the accuracy and the dynamic adaptability of quantum communication protocol security verification are effectively improved.
Owner:BEIJING DUOYAN SILICON VALLEY TECH DEV CO LTD

A method of optimizing linear transformation

A method and system for optimizing compute runtime and memory footprint of a linear transformation process are provided. The method includes determining a set of optimal rotation parameters, wherein the optimal rotation parameters provide an optimal tradeoff between runtime compute resources and a memory footprint for a runtime execution of the linear transformation process; initializing the linear transformation process to run a boosting technique with the determined set of optimal rotation parameters, wherein the boosting technique, when executed at runtime as part of the linear transformation process, performs at least one iteration that yields rotated ciphertexts, and wherein the at least one iteration is based on the determined set optimal rotation parameters and at least one key switching key (KSK); and loading the initialized linear transformation process to an internal memory of a hardware accelerator.
Owner:CHAIN REACTION LTD

IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Owner:MIXUAN TECHNOLOGY (HANGZHOU) CO LTD

IPSec VPN security gateway communication method fused with post quantum cryptography technology

The invention discloses an IPSec (Internet Protocol Security) VPN (Virtual Private Network) security gateway communication method fused with a post quantum cryptography technology, which comprises the following steps of: S1, in a first-stage main mode of IKE (Internet Key Exchange) key agreement, replacing a traditional single SM2 algorithm and a digital certificate based on an SM2 cryptographic algorithm with an SM2 and PQC mixed algorithm and a mixed PQC digital certificate; s2, the initiator and the responder respectively use the PQC encryption key pair and the PQC signature key pair to carry out key exchange and data signature, and simultaneously use the SM2 encryption key pair and the SM2 signature key pair to carry out key exchange and data signature; s3, in the message 1, the initiator sends a security alliance load containing the attribute of the fused SM2 and PQC algorithm to the responder; s4, in the message 2, the responder feeds back a PQC series hybrid certificate and an SA proposal; and S5, in the message 3 and the message 4, the initiator and the responder complete key exchange and verification. According to the invention, the security of the IPSec VPN security gateway can be improved, and quantum computing attacks can be resisted.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Method for enhancing key-switching efficiency following modraise in fully homomorphic encryption

A method and system of the device may include identifying, in an FHE program, key-switching operations occurring after a ModRaise operation. In addition, the device may include determining a first aggregated polynomial sum and a second aggregated polynomial sum; and configuring instructions for performing a MultSum operation based on the determined first aggregated polynomial sum and the second aggregated polynomial sum, the instructions are programmed to be executed during runtime, where the MultSum operation outputs two polynomials, each of which is an inner product between a single cyphertext polynomial and the first aggregated polynomial sum and a single cyphertext polynomial and the second aggregated polynomial sum, thereby reducing memory usage and computational overhead and enhancing key-switching efficiency.
Owner:CHAIN REACTION LTD

Internal and external network audio and video secure transmission method and system based on cloud platform

The invention relates to the technical field of audio and video transmission, in particular to an internal and external network audio and video secure transmission method and system based on a cloud platform. By combining the load balancing technology with the real-time load state and the audio and video stream characteristics of the cloud platform, the encrypted traffic can be dynamically distributed to a plurality of back-end servers, and the calculation overhead in the encryption process can be effectively reduced through selection of the lightweight asymmetric encryption algorithm and the optimized key exchange process; in a handshake stage, by optimizing a key negotiation process and adjusting a key exchange process according to segmentation characteristics, the execution efficiency of a protocol is further improved, and by dynamically adjusting the execution opportunity of encryption operation, it is ensured that the encryption operation is executed at a proper opportunity, and the encryption efficiency is improved. By monitoring and adjusting the load distribution strategy and the encryption parameters in real time, the system operation mode can be dynamically adjusted according to the distortion degree and the transmission state of the audio and video streams, and the distortion degree of the audio and video streams is effectively reduced.
Owner:HANGZHOU XUNCHUAN TECHNOLOGY CO LTD

Network communication dynamic encryption method, encryption and decryption system, equipment, medium and product

The invention discloses a network communication dynamic encryption method, an encryption and decryption system, equipment, a medium and a product, and relates to the technical field of communication. The method comprises the steps that a dynamic factor is obtained through a Berkley packet filter function, a key is generated based on the dynamic factor, the key generated based on the dynamic factor has high randomness and unpredictability, and the problem that a fixed key is adopted in a traditional encryption mode, and consequently the key is prone to being cracked can be solved; moreover, by using the execution environment of the Berkley packet filter function in the kernel mode, the risk that the key is stolen in the transmission and storage process is reduced, the influence on the network communication performance is small, and the network communication encryption efficiency and the network communication security are improved. Moreover, the information of network communication is used as the basis of key generation, additional key distribution and storage management processes are not needed, complex key exchange and certificate management mechanisms are not needed, the key management process is simplified, and the operation and maintenance cost of the system is reduced.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Secure node exchange attribute-based keys (SNEAK)

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for Secure Node Exchange Attribute-based Keys (SNEAK) including secure exchange of sensitive message elements between sequential message nodes using attribute-based key management. Each message node can access none, one, some, or all encrypted message elements based on assigned attributes of that message node. A key management node provides key exchange for each Content Encryption Key (CEK) used to protect the message elements based on attributes of the message nodes.
Owner:WELLS FARGO BANK NA

IPSec VPN security gateway communication method based on post quantum cryptography

The invention discloses an IPSec VPN security gateway communication method based on a post quantum cryptography technology, and the method comprises the following steps: S1, replacing a conventional SM2 algorithm and a certificate with a PQC algorithm and a digital certificate in a first-stage main mode of IKE key negotiation; s2, the initiator and the responder respectively use the PQC key pair to complete key exchange and signature; s3, in the message 1, the initiator sends a security alliance load containing a PQC public key algorithm attribute to the responder; s4, in the message 2, the responder sends an SA load containing a PQC signature certificate and an encryption certificate, and a received SA proposal sent by the initiator is marked; s5, in the message 3 and the message 4, the initiator and the responder complete key exchange and verification; and S6, in the message 5 and the message 6, the initiator and the responder encrypt the transmitted information by using a symmetric cryptographic algorithm, and identify the previous exchange process. According to the invention, the security of the IPSec VPN security gateway is improved, and quantum computing attacks can be resisted.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Key exchange system, hub apparatus, QKD apparatus, method, and program

A key exchange system according to an aspect of the present disclosure includes: a plurality of quantum key distribution (QKD) apparatuses that executes a quantum key distribution protocol including at least error correction; and a plurality of hub apparatuses that performs encrypted communication with each other, in which each of the hub apparatuses includes a key generation unit configured to generate an encryption key for performing the encrypted communication with another hub apparatus based on information received from a corresponding one of the QKD apparatuses, and each of the QKD apparatuses includes a QKD processing unit configured to execute the quantum key distribution protocol with another QKD apparatus and generate a correction key from a ciphertext of random number information, and a first transmission unit configured to transmit information representing a result of basis reconciliation in the quantum key distribution protocol to a corresponding one of the hub apparatuses.
Owner:NT T INC

Internet of Things equipment security authentication and data encryption transmission system and method

The invention relates to the technical field of Internet of Things equipment, particularly provides an Internet of Things equipment security authentication and data encryption transmission system and method, and solves the problems of limited equipment resources and difficult key management. The system comprises an equipment identity authentication component, a key management component and a lightweight encryption component. The method comprises the following steps: authenticating the legal identity of the Internet of Things equipment by adopting a lightweight symmetric key; the authority is dynamically adjusted according to factors such as equipment position, time and network state; the Internet of Things equipment generates and distributes a secret key after passing the access authority authentication; key exchange is carried out between the Internet of Things devices by adopting a key exchange protocol, and local key management is realized at an edge node in combination with edge calculation; and transmitting the data containing the key and the key exchange protocol to the target equipment, encrypting the transmitted data by adopting lightweight encryption and a Hash algorithm during transmission, and preventing a replay attack by using a timestamp and a random number. According to the invention, comprehensive safety protection of the Internet of Things equipment is realized.
Owner:SHENZHEN AISHANSI TECHNOLOGY CO LTD

Timing sequence post-synchronization quantum key extraction method based on classical information fusion

A time sequence post-synchronization quantum key extraction penetration test method comprises the following steps: A) under the condition of penetration test, a QKD system operates normally, and a sending end and a receiving end smoothly complete key distribution; b) the man-in-the-middle selects an initial original key exchange period to establish synchronization and correlation so as to realize clock synchronization with a receiver; c) analyzing quantum bit error rate information obtained from a public channel by a man-in-the-middle, deducing a corresponding relation between a receiver detector and each quantum state, and establishing a mapping model of the quantum states and bit values; d) determining a quantum state type responded by the receiver in each response time slot in a subsequent original key exchange period by the middleman in combination with path information obtained by other sub penetration tests; and E) the intermediary obtains a final key which is the same as the two communication parties by implementing an error correction and privacy amplification process, the quantum bit error rate between the intermediary and the sender is maintained at a relatively low level and is lower than a security threshold, and a security alarm is not triggered in a penetration test process.
Owner:NAT UNIV OF DEFENSE TECH

KEM-based anti-quantum TLCP protocol design method and system

The invention provides a KEM-based anti-quantum TLCP protocol design method and system, and belongs to the technical field of information security. The method comprises the steps that a server side applies for a server side signature certificate and an encryption certificate from an issuing mechanism, a long-term server side signature public key is stored in the server side signature certificate, and a long-term server side encryption public key is stored in the encryption certificate; and in the TLCP handshake protocol, identity authentication and key exchange between the server and the client are realized based on the long-term server signature public key and the long-term server encryption public key. According to the method, the anti-quantum KEM is used for replacing signature and encrypted primitives to realize key exchange and identity authentication functions of the protocol, identity authentication does not depend on the signature of a message any more, and meanwhile, a client introduces a temporary public key to replace a long-term static public key to participate in a KEM key negotiation process, so that the forward security of the protocol is ensured, and the security of the protocol is improved. Therefore, the efficiency and the security of the TLCP protocol are improved.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Wireless audio transmission protocol optimization algorithm for low-delay dynamic password

The invention discloses a wireless audio transmission protocol optimization algorithm for a low-delay dynamic password, which comprises the following steps of: generating an initial encryption key: before audio data transmission starts, generating the initial encryption key according to a current network environment, equipment computing power and audio transmission requirements; the encryption key can be generated based on a timestamp, a random number or a key exchange protocol, the randomness and the safety of the encryption key are ensured, and a proper encryption algorithm is selected: according to equipment computing resources and network conditions, a proper low-delay encryption algorithm is selected. By selecting a low-delay encryption algorithm and dynamically adjusting the encryption complexity, the influence of the encryption process on transmission delay is remarkably reduced, the real-time performance of audio transmission is optimized, the reliability of key synchronization in a wireless network is ensured through a redundant synchronous data packet and a regular key synchronization mechanism, and even if signal loss or interference occurs, the reliability of key synchronization in the wireless network is ensured. And synchronization can be recovered in time, so that decryption failure caused by asynchronous keys is avoided.
Owner:同辉佳视(北京)信息技术股份有限公司

Server cipher machine communication method and system based on RDMA technology

The invention discloses a server cipher machine communication method and system based on an RDMA technology. According to the method, physical direct connection between a device end and an agent end is achieved by establishing an RDMA reliable connection channel; bidirectional authentication is carried out based on an SPDM protocol; a random challenge is generated after the device side verifies a proxy side certificate, and key exchange is triggered after a proxy side private key signature response and the verification of the device side are passed; the two parties adopt an SM2 public key algorithm to generate a shared key and derive a session key KEK; the proxy end encrypts the request data by using the KEK, and writes the encrypted data into the SMZ secure memory of the equipment end through the RDMA Write; the equipment end processes data through a hardware password engine, and directly writes an additional timestamp, a serial number and a result packet of MAC authentication to an appointed address of the agent end through RDMAWrite; and when the communication is finished, the device end erases the key and resets the engine. According to the invention, the problems of large delay, low throughput, low security, large CPU occupancy rate and the like in the prior art can be solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Access control authentication method based on multi-modal dynamic challenge and block chain auditing

The invention discloses an access control authentication method based on multi-modal dynamic challenge and block chain auditing, and belongs to the technical field of access control authentication, and the access control authentication method comprises the following steps: collecting video, sound and motion data of a user, and carrying out dynamic living body detection; after detection is passed, face features, voiceprint features and gait features are extracted and subjected to fusion scoring, and after the score exceeds a threshold value, equipment trust chain verification is carried out according to a dynamic token generated after secret key exchange between the APP and the access control terminal; after the verification is passed, firstly performing deep counterfeiting detection on the whole face, and then performing deep counterfeiting detection on the details of the face; and finally, the authentication passing information is stored in the block chain, TxID verification is carried out when a receipt of certificate storage transaction success returned by the block chain is received, and the door is authorized to be opened after the verification is successful. According to the invention, forgery attacks can be effectively resisted, the false identification rate and the missed identification rate of the access control system are reduced, the auditing tracking and tamper-proof capabilities are greatly enhanced, and the identity authentication reliability in a high-security scene is guaranteed.
Owner:NANJING INST OF TECH

Anti-quantum key packaging method and device, medium and equipment

The invention discloses an anti-quantum key packaging method and device, a medium and equipment, and the method comprises the steps that a first node generates a first public key and a first private key based on an asymmetric encryption algorithm, and generates a second public key and a second private key based on an anti-quantum encryption algorithm; sending the first public key and the second public key to a second node, so that the second node encrypts a third public key based on the second public key to obtain a public key ciphertext, and generates a shared key based on the first public key and a third private key; receiving a public key ciphertext sent by the second node, and decrypting the public key ciphertext based on the second private key to obtain a third public key; generating the shared key based on a third public key and the first private key; wherein the third public key and the third private key are generated by the second node based on an asymmetric encryption algorithm. According to the invention, by combining an anti-quantum encryption algorithm and a widely used asymmetric encryption algorithm, a secure key exchange mechanism which can resist future quantum computing threats and has high compatibility is provided.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Active prevention measure and system based on individual emergency protection

The invention discloses an active prevention measure and system based on individual emergency protection. The method comprises the steps of hardware module integration and test, core function logic development, cloud system architecture construction, power supply and industrial design and system integration and compliance authentication. The invention belongs to the technical field of campus safety, and particularly relates to an active prevention measure and system based on individual emergency protection, and the scheme adopts a magnetic latching relay to realize physical disconnection, adopts a dual authentication process, sets a one-way communication system, and carries out dynamic sound pressure adjustment based on environmental noise; an end-to-end encryption channel is developed, a double-encryption mode is adopted, a dynamic fragmentation storage technology is applied, an encryption channel is established, key exchange and video fragmentation hash verification are adopted, an equipment state vector is defined, and a 3D convolutional neural network is adopted to identify violent behaviors.
Owner:薛静

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

Modbus credibility enhancement method and device based on national cryptographic algorithm and storage medium

The invention relates to the technical field of industrial communication, in particular to a Modbus credibility enhancement method based on a national cryptographic algorithm, which comprises the following steps: S1, a client sends identity authentication message information including a time factor, a random number, a client public key and an abstract to a server to complete public key exchange, identity authentication is carried out on the two communication parties through a transmission session identifier; s2, the client sends a key negotiation message to the server, and generates an exclusive key of the session after receiving a server key parameter returned after the server successfully verifies the key negotiation message; s3, key verification is carried out between the client and the server; and S4, the client encrypts a Modbus credible message carrying a time factor, a random number and a Modbus command through the exclusive key of the session, and then sends the Modbus credible message to the server, and the server analyzes and replies the Modbus credible message. According to the method, an identity verification process is added, so that other PLCs are prevented from being operated by mistake in a PLC login scene, and the replay resistance and tamper resistance of the message are ensured through a time factor, a random number and an abstract.
Owner:ZHEJIANG SUPCON RES +1

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Hybrid encryption method and device and storage medium

The invention provides a hybrid encryption method and device and a storage medium, and the method comprises the steps: a client generates a short-term SM2 key pair and exchanges with a server after obtaining a long-term SM2 key pair and a server public key, dynamically generates a session SM4 symmetric key through an SM2 key exchange protocol, and finally achieves the data transmission and response processing through the session SM4 symmetric key. Through the implementation of the scheme of the invention, the client not only establishes the basic trust relationship based on the long-term SM2 key pair, but also generates the short-term SM2 key pair during each service request, and dynamically derives a unique session SM4 symmetric key and an initial vector by cooperatively executing the SM2 key exchange protocol with the short-term key of the server. And each request has an independent security context, so that the decryption risk after the session key is reused or stolen is fundamentally prevented, and the end-to-end dynamic security communication under the national secret system is really realized.
Owner:SHANGHAI FEIWEI INFORMATION TECH CO LTD +2

Zero-trust gateway single packet authentication method and system for new energy fan control system, computing equipment, computer storage medium, computer program product and chip

The invention discloses a zero-trust gateway single packet authentication method and system for a new energy fan control system, computing equipment, a computer storage medium, a computer program product and a chip. The authentication method comprises the steps of generating an authentication material; exchanging and deriving a mixed key; binding Hash calculation is carried out; encrypting and assembling the message; receiving and verifying by the gateway; and binding verification and registration are carried out. The invention relates to a zero-trust gateway single packet authentication method combining a post quantum cryptography algorithm and a national commercial cryptography algorithm. The method is applied to secure communication between a wind power plant and a centralized control center, an SM2, SM3 and SM4 combined algorithm in a national secret system is combined with a post-quantum key agreement algorithm CRYSTALS-Kyber512, identity authentication, encryption and integrity verification are completed through a single message, confidentiality protection and anti-quantum security guarantee under one-time interaction are achieved, and the security of the wind power plant is improved. The method is especially suitable for new energy scenes with wide fan distribution, complex links and high real-time requirements.
Owner:DATANG HUAXIAN WIND POWER GENERATION CO LTD

Always Connected Drone Systems

A communication system is disclosed for maintaining persistent and secure wireless communication between a drone and a controller using an always connected mode. The drone operates as an 802.11 access point (AP), while the controller operates as a station (STA). During initial connection, the system performs a standard 802.11 association and key exchange, and stores the resulting association context, including the association response and encryption keys, to persistent memory. Upon detecting a disconnection or reboot, the system restores the saved context directly into the wireless driver to reinitialize MAC state and resume encrypted communication without repeating full association. The system includes modifications to wpa_supplicant, hostapd, and wireless drivers to support direct injection of association context and to temporarily disable replay protection. A dynamic switching mechanism selects between standard association and always connected mode based on runtime conditions such as link quality, proximity, or session validity.
Owner:SKYDIO INC

Private key full-life-cycle security management system and method based on mobile terminal anti-quantum cryptography algorithm

The invention provides a private key full-life-cycle security management system and method based on a mobile terminal anti-quantum cryptography algorithm. The method comprises the following steps: generating a key pair based on the anti-quantum cryptography algorithm; acquiring a certificate containing a public key in the key pair; calling a mobile terminal key management system to generate a symmetric encryption key, encrypting a private key in the key pair by using the symmetric encryption key, storing the encrypted private key into a sandbox, and storing a certificate into the sandbox; extracting a private key and a certificate in the encrypted key pair from the sandbox, calling the hardware-level key management system, and decrypting the private key by using the symmetric encryption key to obtain a decrypted private key; calling an interface matched with the purpose of the private key through a preset anti-quantum algorithm library, and executing signature, signature verification or key exchange operation by using the decrypted private key; and after the operation is completed, clearing the memory area for storing the private key plaintext. According to the method, the life cycle of the anti-quantum private key can be safely managed on the premise of not depending on the native support of a mobile system.
Owner:DONGFENG MOTOR GRP

Privacy protection federated learning method based on result-agnostic function encryption

The invention discloses a privacy protection federated learning method based on result-agnostic function encryption, and the method comprises the steps: dividing a derived key assembly into a plurality of shares, and carrying out the reconstruction through the remaining shares even if a part of clients are offline and the key shares are missing, thereby guaranteeing that a function key can be recovered, and an encryption model can be correctly aggregated, and improving the privacy protection efficiency. And the robustness and fault tolerance of the system are greatly improved. A non-interactive key exchange technology is adopted, and a secret sharing mechanism is combined, so that a client can generate a private key in a collaborative manner under the condition that no trusted third party participates, the deployment complexity is reduced, and the security and expandability of the system are improved. A function encryption process with an unknown result is designed, only an intermediate result in an encrypted state is output in an aggregation stage, and decryption is finally completed by local joint of a client, so that the possibility of snooping an aggregation result and reversely deducing original data by a server under a semi-honesty model is fundamentally avoided, and data privacy in a federated learning process can be effectively guaranteed.
Owner:SOUTH CHINA AGRICULTURAL UNIVERSITY

Electric power metering network security protection system and electric quantity acquisition data encryption transmission protocol

The invention provides an electric power metering network security protection system and an electric quantity acquisition data encryption transmission protocol used by the same. The system comprises a metering terminal, an edge gateway and a master station platform. The metering terminal is integrated with a domestic commercial password chip, adopts a three-level safety start chain and a data disturbance encryption mechanism, and has the functions of side channel protection and physical disassembly detection; the edge gateway constructs a multi-channel SM4 encryption assembly line based on the FPGA to realize encryption relay and data caching; the master station platform supports high-concurrency encryption session management, dynamic key updating and LSTM model driven abnormal traffic detection. The matched data encryption communication protocol is based on a state machine model and comprises the stages of time synchronization, key exchange, data transmission, integrity verification and the like. The system has high security, high real-time performance and strong environment adaptability, and is suitable for security access scenes of various power terminals such as intelligent electric meters, concentrators, micro-grid metering and the like.
Owner:MARKETING SERVICE CENT OF STATE GRID QINGHAI ELECTRIC POWER CO +1

Secure sniffing of wireless connections with forward secrecy

In at least one example, a method includes establishing, by a sniffer provisioning server (SPS) of a first wireless device, a trusted relationship between the first wireless device and a sniffer tool using a public key of the sniffer tool. An out-of-band (OOB) key exchange provisions the public key of the sniffer tool to the wireless device. The method further includes obtaining, by the SPS, key material uniquely related to a communication session established between the first wireless device and a second wireless device using a shared password. The key material excludes the shared password and a session key uniquely related to the communication session. The method further includes publishing, by the SPS, the key material over a channel to the sniffer tool based on the trusted relationship. The channel is secured using the public key of the sniffer tool.
Owner:TEXAS INSTRUMENTS INC

Key exchange system, QKD apparatus, hub apparatus, method, and program

A key exchange system includes a quantum key distribution (QKD) network including a plurality of QKD apparatuses that performs exchange of a key by using a quantum key distribution protocol and a key management apparatus that relays the key; and a plurality of hub apparatuses that performs encrypted communication by using the key received from the key management apparatus. Each of the QKD apparatuses includes a processor configured to encrypt the key by using a public key of one of the hub apparatuses in a case where the key is exchanged with another QKD apparatus by using the quantum key distribution protocol, and transmit the encrypted key to the key management apparatus. Each of the hub apparatuses includes a processor configured to decrypt the encrypted key by using a secret key corresponding to the public key in a case where the encrypted key is received from the key management apparatus.
Owner:NT T INC